The Senate 


Select Committee on Foreign 
Interference through Social Media 


Senate Select Committee on Foreign 
Interference through Social Media 


August 2023 


© Commonwealth of Australia 2023 
ISBN 978-1-76093-525-2 (Printed version) 
ISBN 978-1-76093-525-2 (HTML version) 


This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivs 
4.0 International License. 


002e 


The details of this licence are available on the Creative Commons website: 
https://creativecommons.org/licenses/by-nc-nd/4.0/. 


Printed by Printed by the Senate Printing Unit, Parliament House, Canberra 


Contents 


IVI RNID CUS iss sie ss stesed snadsiccnsets cienassusvseetysesitnsssascesavasussssisusdeystatious sivdodesaWiasddebiaiteavsosadods vaassecndetinsatranstetesstesves v 
Abbreviations ánd'acrony MS. a a a ai vii 
OEE W ON EEE E E T EEE TE xi 
List of recommendations aswis cisessucussezecsicstnnesensuviedessstoucessupusdecovasscoudupissabseteasetsspes sdipiasesetdeatasabsatoasts XV 
Chapter 1—Introduction and background .......sesessesesseseseesesessescoresessosceresessoseseeseseoseseosesessoseeesessese 1 
Deion Saa e a TE A E E EEO E E E E E EA 2 
Whatisforeigninterferente n sinse ies ovis oaia oske Es enea ia ELE aaan AER OERLE STERE ETETEA rinek iaso E EEE 4 
Foreign interference via social media..............sssssesesestessestestsseesesresstssestessestesesntestsneesessestessesreseeneenes 5 
Chapter 2— Foreign interference in Australia .......sessssessosesessossosesessoscososessosersosessosorsosesessossesesessose 9 
Foreign iñtetferencein Australiassa n a ae att a a aE 9 
BUCS gi nonno seias e E EE EEA RAA ES EEE E EEA E EEAS E EEKE EES at EEEo 22 
Emerging TACHI CE ieser rrinin seesnpiis okey hatin hae nren Eees nB E Oone a eanas EEEN E SEENED e EKE saranin eee E e 26 
Chapter 3— International iSSUes........esessssssesesosesesesesessssesosososossssosesososesesessssosssesososovosessssesesosesesesssso 31 
109E) 01 T E E E E E 31 
United'State Sinanin a a ia ea a a 41 
United Kiņngdoni sna a a anaa ola Set dia Ni a aaa a aaa coll teas A 43 
Canadai. reroror esi aaa E E IE E E ETE or A EE EE Reed ae EEA 44 
New Zealand oirn pals cease ca e a a e a a e e a a a a a 45 
Pacific LOO VON hess iiie eeii eens anera R i AE iconic E A AE ela AAE ERE EE EEE EEE A AAR E ele 46 
International digital literacy campaigns sansiecisntitrcctebactcta aan tuaceebsinadbaeam dae ciantate 47 
Chapter 4— Government: Current practice ............ccscssssssssscssssscessessssesessersscesessecsssesneseesesessesees 51 
Cuürrert legislative Seneiii gs siete tie tatect ni en beds as aee o Ea E aE EE EEE 51 
Government counter-interference CNntities...........cscssessescessersercssssrsscssnssersessersscssassesesserseessessonees 54 
Recent policy responses and initiatives x. :cccsscsssesssesesesesvscseseewesicievsnyratarcesedeacsesesdesserececeseaivoenossadtins 62 
Chapter 5— Government: ideas for action.........ssessesesessossososessossesosessosorsoseseososcosesessosessosessosessesesee 69 
Lead AS CHOY iils ertet eden cu vog teed cus e eiaa eE ea Aa S EEE EE AAEE AG tat 70 
standards-based tegülatioNi s esyngnninn naien n o a Eiin 71 
Legal remedies iniia at esc aaa a coe ea cael eda E E aE e r NA 76 
COU MPSA SSS UNS riesia ei aore rnei a EEE EEEE REENE EE ERNE EE T ia eiaa 81 
Cross-sector CollaDOra Onl va nescera aE E E E a E i i E i 84 


iii 


Chapter 6—Platforms— Current practice and identified gaps ........ssscssccssssesssssssscesecessesesenes 87 


Platform responsibilities sss eraa eria Aea vest Esaera EEEa en eee set ar cet 87 
Platform actions to address interference ........seesseeeeeeiseeeererisesesesrsrrtstststeteretrererserenestsesrsertntststete 88 
QNE O UN CONICET INS aac ae i eE aie EEEE E TE TE E ERTE ETE E E AE 92 
Platforms and authoritarian states .......seseseseseseeseseeeeeeseststsrsrsrsssstststeretrererrtsrseseseesstrtntststerererreeeeses 106 
Chapter 7—Building the capacity of civil society.........seesessseorsosesessossososessossreosessosossosesessosseseses 125 
A role for civil society organisations, expert centres and researchers.............essesssseesesissesesee 125 
Building resilience through public education...........ss.sssssesssssessessessessestesesstestsrensesressessentenseseesesne 128 
Mainstream medianscnnisninpniaeois p a E a A Gtaveies 137 
Diaspóra COMME esee io ni cea tenaslesouiols iE eraa Ee TEE are ERR TEE a EET N a E E 138 
Chapter 8— Committee view and recommendations ....ssesessssososesesesesesesesrososososeseeeosososeseseseseses 143 
Oyerall committee View e e eaa Ee e A EAE E E eE nurs Rada e E os Poaceae 143 
Platforny transparency saririsa iian eari ren REE E AE EER A a aE 145 
Platforms headquartered in authoritarian states „..........ss.sssssesseseessessestessestestsrersessessessestesseseesense 150 
Building the capacity of government ...........sssesessssseseesiesssseesesressessessessestessesiestsnensesnessessestensestesenne 157 
Intelligence priefifig Sanni nasiran a a aaa Sele a S aE 161 
Building thè capacity of civil SOC nesoni ena iier ea a s i a elcanltcces 162 
Protecting OUT NEI SMD OUTS ccc caves eieiei aerats iieiea saski ii nahs aasit iega sie ia 167 
Additional comments from Government Senators ........cccssssssssessscscssssssssscssscsssssssssssssseseseees 169 
Australian Greens' Additional Comments.......e..ssessesesesseseoresessoseseeseseesescoresessoseeeesesreseseesesessereee 173 
Appendix 1— Submissions, tabled documents and additional information.................000 175 
Appendix 2— Public hearings and witnesses .....esesesesesesesessesososesereseosososeseseseseseseosovososerereesoseses 179 
Appendix 3— 46th Parliament inquiry recommendations ...ssssesesesessososeseseseseseseososososeseresseseses 183 


Members 


Chair 

Senator James Paterson LP, VIC 
Deputy Chair 

Senator Jess Walsh ALP, VIC 
Members 

Senator Claire Chandler LP, TAS 
Senator Raff Ciccone ALP, VIC 
Senator Sarah Hanson- Young AG, SA 
Secretariat 


Ms Apolline Kohen, Committee Secretary 

Dr Sean Turner, Committee Secretary 

Ms Kate Gauthier, Principal Research Officer 
Ms Monique Nielsen, Senior Research Officer 
Ms Georgia O'Connor, Administrative Officer 
Ms Ella Shea, Administrative Officer 

Ms Stacey Sullivan, Administrative Officer 


Po Box 6100 Email: foreigninterference47.sen@aph.gov.au 


Parliament House 


Canberra ACT 2600 


5D 
AAP 


ABCDE framework 


ACCC 
ACMA 
ACRI 


ACSC 

ADM 

AEC 

AFP 

AFP 

AGD 

AHRC 

AI 

Allens Hub Joint 
Submission 


API 
ASD 
ASEAN 
ASIO 
ASPI 
bots 


CALD 
CCP 
CFI 
CIB 
CISA 
CISC 
CLO 
COO 
Criminal Code 
CSIS 
CSO/s 


Abbreviations and acronyms 


dismiss, distort, distract, dismay, divide objectives 
Australian Associated Press 

actors, behaviours, content, degree, and effect 
framework 

Australian Competition and Consumer Commission 
Australian Communications and Media Authority 
Australia-China Relations Institute, University of 
Technology Sydney 

Australian Cyber Security Centre 

automated decision making 

Australian Electoral Commission 

Australian Federal Police 

Agence France-Presse 

Attorney-General's Department 

Australian Human Rights Commission 

artificial intelligence 

University of New South Wales Allens Hub for 
Technology Law and Innovation, Deakin University 
Centre for Cyber Security Research and Innovation and 
Institute of Electrical and Electronics Engineers Society 
on Social Implications of Technology 

application programming interface 

Australian Signals Directorate 

Association of Southeast Asian Nations 

Australian Security Intelligence Organisation 
Australian Strategic Policy Institute 

robots or algorithmically-driven computer programs 
designed to carry out specific tasks online, for example, 
mimicking the behaviour of real users 

culturally and linguistically diverse 

Chinese Communist Party 

counter foreign interference 

co-ordinated inauthentic behaviour 

Cybersecurity and Infrastructure Security Agency (US) 
Cyber and Infrastructure Security Centre 

Community Liaison Officer 

Chief Operating Officer 

Criminal Code Act 1995 

Canadian Security Intelligence Service 

Civil Society Organisation/s 


vii 


DC 

Defence and Security 
Institute 

Department of 
Communications 
DIGI 

DIGI Code 


DISARM framework 


EC 
EEAS 
EEAS report 


EFI 

EIAT 

Electoral committee 
ENISA 

Espionage Act 


EU 
FADT committee 


FIMI 
FIS 
FITS 
FMIC 
FORT 


GDPR 

GPS 

Home Affairs 
HUMINT 
IEEE 

IEEPA 

IMSI 

INGE 


INSLM 

IP 

IRI 

Law Council 


District of Columbia (Washington, DC, US) 
Defence and Security Institute, University of Adelaide 


Department of Infrastructure, Transport, Regional 
Development, Communications and the Arts 

Digital Industry Group Inc 

Australian Code of Practice on Misinformation and 
Disinformation 

Disinformation Analysis and Risk Management 
framework 

European Commission 

European External Action Service 

1st EEAS Report on Foreign Information Manipulation and 
Interference Threats 

espionage and foreign interference 

Electoral Integrity Assurance Taskforce 

Joint Standing Committee on Electoral Matters 
European Union Agency for Cyber Security 

National Security Legislation Amendment (Espionage and 
Foreign Interference) Act 2018 

European Union 

Senate Foreign Affairs, Defence and Trade references 
committee 

foreign information manipulation and interference 
foreign intelligence services 

Foreign Influence Transparency Scheme 

Foreign Malign Influence Centre (US) 

Facebook Open Research and Transparency Initiative 
(Meta) 

General Data Protection Regulation (EU) 

Global Positioning System 

Department of Home Affairs 

human intelligence 

Institute of Electrical and Electronics Engineers 
International Emergency Economic Powers Act (US) 
International mobile subscriber identity 

Special Committee on Foreign Interference in all 
Democratic Processes in the European Union, including 
Disinformation 

Independent National Security Legislation Monitor 
Internet protocol 

Islamic Republic of Iran 

Law Council of Australia 


viii 


News and Media 
Research Centre 
NGO/s 

NSW 

OpenCTI 

OSINT 

PCIO 

PJCIS 


PR 

PRC 
PSPF 

the Quad 


RESTRICT Act 


SBS 

SOCI Act 
SOCMINT 
STIX™ 
TAG 


Tibetan Association 


ToR 
TOR 
TTPs 
TV 
UFIT 
UFWD 
UK 

US 
VLOP/s 


News and Media Research Centre, University of 
Canberra 

non-government organisation/s 

New South Wales 

Open Cyber Threat Intelligence [platform] 
open-source intelligence 

Partnership for Countering Influence Operations 
Parliamentary Joint Committee on Intelligence and 
Security 

public relations 

People's Republic of China 

Protective Security Policy Framework 

Quadrilateral Security Dialogue between Australia, 
India, Japan and the US 

Restricting the Emergence of Security Threats that Risk 
Information and Communications Technology Act (US) 
Special Broadcasting Service 

Security of Critical Infrastructure Act 2018 

OSINT gathered from social media platforms 
Structured Threat Information Expression [data format] 
Threat Analysis Group 

Australian Tibetan Community Association 

terms of reference 

The Onion Router 

tactics, techniques and procedures [of threat actors] 
television 

University Foreign Interference Taskforce 

United Front Work Department (China) 

United Kingdom 

United States of America 

very large online platform/s 


Foreword 


Foreign interference is now Australia's principal national security threat which 
risks significantly undermining our values, freedoms and way of life. Australia 
has been a world leader in combatting foreign interference, however, 
authoritarian regimes continue to pose an unacceptable risk to democratic 
societies through targeted online disinformation campaigns that leverage social 
media platforms to skew public debate, undermine trust in our democratic 
institutions, and establish narratives that favour the interests of authoritarian 
states. The proliferation of emerging technologies like artificial intelligence has 
made their job easier, and demonstrates the need for urgent action to ensure 
Australia stays ahead of the threat. 


Foreign interference is clandestine activity carried out by, or on behalf of, a 
foreign regime to corrupt our decision-making, political discourse and societal 
norms. The scale, speed and ease at which these activities can be conducted 
online means social media is increasingly being weaponised to spread 
disinformation to deliberately mislead or obscure the truth for malicious or 
deceptive purposes. Authoritarian regimes like China and Russia are deploying 
new methods for cyber-enabled disinformation activities as part of a broader, 
integrated strategic campaign to advance their own national interests at 
Australia's expense. 


Whether we like it or not, social media platforms are today not just the dominant 
communications channels in modern economies, they constitute the public 
square for democracies. They are the place where news is first reported, 
contentious issues are debated, consensus is formed and public policy decisions 
are shaped. The health of these forums directly affects the health of our 
democracies. 


Foreign authoritarian states know this. They do not permit open and free 
debates on their own social media platforms. They use ours as a vector for their 
information operations to shape our decision-making in their national interest — 
contrary to ours. 


Effectively countering foreign interference through social media is therefore one 
of Australia's most pressing security challenges. That is why on 
24 November 2022 the Senate resolved to establish the Select Committee on 
Foreign Interference through Social Media to investigate the risk posed to 
Australia's democracy from foreign interference through social media, to 
expand on the work of the 46th Parliament which investigated cyber-enabled 
foreign interference. 


As the Australian Security Intelligence Organisation (ASIO) rightly assessed, 
social media itself is not the threat but is a vector for foreign interference. Not all 


xi 


social media platforms are the same, and therefore the ability for an 
authoritarian regime to leverage a platform varies greatly for platforms based 
in authoritarian countries and those that are based in liberal democracies. 


The committee was particularly concerned with the unique national security 
risks posed by social media companies like TikTok and WeChat, whose parent 
companies ByteDance and Tencent respectively, are irrefutably headquartered 
in and run from authoritarian countries like China. China's 2017 
National Intelligence Law means the Chinese Government can require these 
social media companies to secretly cooperate with Chinese intelligence agencies. 
In the case of TikTok, the committee heard that its China-based employees can 
and have accessed Australian user data, and can manipulate content 
algorithms—but TikTok cannot tell us how often this data is accessed despite 
initially suggesting that this information was logged. Nor was TikTok able to 
provide the legal basis upon which its employees can refuse to comply with 
Chinese law —the short answer is, it can't. 


Throughout the inquiry, the committee found social media companies based in 
authoritarian countries demonstrated their reluctance to cooperate with 
Australian parliamentary processes. TikTok was reluctant to provide witnesses 
sought by the committee, and evasive in their answers when they finally did 
agree to appear. WeChat showed its contempt for the Parliament by failing to 
appear before the committee at all, and through its disingenuous answers to 
questions in writing. This stood in contrast to the more constructive engagement 
of platforms based in Western countries who at least recognised the 
fundamental importance of the checks and balances inherent in democratic 
systems. 


The committee was also concerned with the equally serious risk of Western 
social media companies being weaponised by authoritarian regimes to pump 
disinformation into our democracy to influence and undermine our political 
systems. For example, between 2017 and 2022, Facebook's parent company, 
Meta, disabled more than 200 covert influence operations originating from more 
than 60 countries that targeted the public domestic debate of another country. 
In the first quarter of 2023, YouTube terminated more than 900 channels linked 
to Russia and more than 18 000 linked to China. 


In the case of both authoritarian and Western-based social media companies, the 
committee explored concerns that social media platforms are being used to ‘pull’ 
and 'push' information in four ways: to gather intelligence on individuals that 
will enable them to be targeted; to gather behavioural data by population or 
cohort to refine interference campaigns; to harass and intimidate Australia's 
diaspora communities; and to undermine societal trust, spread social disunity 
and influence decision-making through disinformation campaigns. 


Countering this insidious activity becomes more complex as authoritarian 
regimes continue to adapt and evolve their methods. Emerging new technology 
and tactics such as the rise of artificial intelligence and the commercialisation of 
disinformation services, where state actors engage companies to orchestrate 
disinformation campaigns, threatens to exponentially increase the risk of 
foreign interference on social media, necessitating an urgent response. 


Looking to the future, developing a real-time understanding of and response to 
foreign interference through social media is critical to protecting our values, 
freedoms and way of life from interference by foreign regimes. The committee 
believes that strengthening transparency requirements on social media 
companies is critical to ensuring they operate with integrity while also 
preserving the right of Australians to freely communicate and participate in 
public debate online. 


The committee is gravely concerned that the information Australians receive on 
these platforms is being influenced by directions from foreign authoritarian 
governments. That's why we have recommended a range of enforceable 
transparency standards, so that users can both evaluate the content they see on 
these platforms, and the conduct of the platforms themselves. For example, we 
believe state-affiliated media entities should be proactively labelled on all 
platforms. We recommend that any content censored at the direction of a 
government be disclosed to users. Platforms should be open to independent 
external researchers who can identify, investigate and attribute coordinated 
inauthentic behaviour. The access to user data facilitated by these platforms, 
especially to employees based in authoritarian countries, must be disclosed. 


WeChat was found to have comprehensively failed the transparency test by 
refusing to participate in public hearings on the basis that, despite its significant 
digital presence, it does not have a physical presence in Australia. The 
committee therefore recommends that, as part of a suite of transparency 
requirements, social media companies that operate in Australia be required to 
establish a physical presence within Australia's legal jurisdiction so that they 
can be held accountable to our laws. 


The committee found that TikTok engaged in a determined effort to obfuscate 
and avoid answering the most basic questions about the platform, its parent 
company ByteDance and its relationship to the Chinese Communist Party. 
That's one reason why the committee has also recommended that social media 
companies that repeatedly fail to meet the minimum transparency requirements 
should be subject to fines and, as a last resort, may be banned by the 
Minister for Home Affairs with appropriate oversight mechanisms in place. 


Should the United States Government take action to force ByteDance to divest 
ownership of TikTok to another company that is not beholden to the Chinese 


xiii 


Communist Party, the committee finds that Australia should consider similar 
requirements in Australia. 


The serious espionage and data security risks posed by TikTok, which 
necessitated the April 2023 ban on government users downloading the app to 
their devices, must also be confronted by government contractors and critical 
infrastructure providers. Government must also put in place measures to 
anticipate, assess and mitigate the next TikTok before it is widely deployed on 
government devices. 


Deterring this malign online behaviour must be a priority for government. 
Amended Magnitsky sanctions, bolstered enforcement of espionage and foreign 
interference offences and support for diaspora communities targeted by 
transnational repression all need to be part of a package of reforms to raise the 
costs of this activity. 


Of course, social media companies do not need to wait for the government to 
introduce legislation to strengthen transparency on their platforms. They can 
proactively undertake this important task on their accord, as some of them are 
already doing. 


Foreign interference through social media is a real, pervasive and growing 
threat. Despite Australia's world-leading efforts to counter foreign interference 
including through our Espionage and Foreign Interference statutory framework 
and the establishment of a Foreign Influence Transparency Scheme, it is evident 
that there is more work to be done to make Australia an even harder target for 
the sophisticated disinformation campaigns of authoritarian regimes. 


It's not too late to arrest the threat. With a concerted joint effort by government, 
the private sector and civil society, we can ensure Australia's way of life prevails. 


xiv 


List of recommendations 


Recommendation 1 


8.43 The committee recommends the Australian Government require all large 
social media platforms operating in Australia to meet a minimum set of 
transparency requirements, enforceable with fines. Any platform which 
repeatedly fails to meet the transparency requirements could, as a last resort, 
be banned by the Minister for Home Affairs via a disallowable instrument, 
which must be reviewed by the Parliamentary Joint Committee on 
Intelligence and Security. 


8.44 Requirements should include, at minimum, that all large social media 
platforms: 


e must have an Australian presence; 

e must proactively label state affiliated media; 

e must be transparent about any content they censor or account takedowns 
on their platform; 

e must disclose any government directions they receive about content on 
their platform, subject to national security considerations; 

e must disclose cyber-enabled foreign interference activity, including 
transnational repression and surveillance originating from foreign 
authoritarian governments; 

e must disclose any takedowns of coordinated inauthentic behaviour (CIB) 
networks, and report how and when the platform identified those CIB 
networks; 

e must disclose any instances where a platform removes or takes adverse 
action against an elected official's account; 

e must disclose any changes to their platform's data collection practices or 
security protection policies as soon as reasonably practicable; 

e must make their platform open to independent cyber analysts and 
researchers to examine cyber-enabled foreign interference activities; 

e must disclose which countries they have employees operating in who 
could access Australian data and keeps auditable logs of any instance of 
Australian data being transmitted, stored or accessed offshore; and 

e must maintain a public library of advertisements on their platform. 


Recommendation 2 

8.61 The committee recommends that, should the United States Government force 
ByteDance to divest its stake in TikTok, the Australian Government review 
this arrangement and consider the appropriateness of ensuring TikTok 
Australia is also separated from its ByteDance parent company. 


XV 


Recommendation 3 


8.69 The committee recommends the Australian Government extend, via policy or 
appropriate legislation, directives issued under the Protective Security Policy 
Framework regarding the banning of specific applications (e.g. TikTok) on all 
government contractors’ devices who have access to Australian government 
data; and 


8.70 The Minister for Home Affairs should review the application of the 
Security of Critical Infrastructure Act 2018, to allow applications banned 
under the Protective Security Policy Framework to be banned on work-issued 
devices of entities designated of Systems of National Significance. 


Recommendation 4 


8.71 The committee recommends the Australian Government consider extending 
the Protective Security Policy Framework directive banning TikTok on 
federal government devices to WeChat, given it poses similar data security 
and foreign interference risks. 


Recommendation 5 


8.72 The committee recommends the Australian Government continues to audit 
the security risks posed by the use of all other social media platforms on 
government-issued devices within the Australian Public Service, and issue 
general guidance regarding device security, and if necessary, further 
directions under the Protective Security Policy Framework. 


Recommendation 6 


8.73 The committee recommends the Australian Government establish a national 
security technology office within the Department of Home Affairs to map 
existing exposure to high-risk vendors such as TikTok, WeChat and any 
similar apps that might emerge in the future. It should recommend 
mitigations to address the risks of installing these applications, and where 
necessary, ban them from being installed on government devices. 


Recommendation 7 


8.80 The committee recommends the Australian Government designate an entity 
with lead responsibility for whole-of-government efforts to counter 
cyber-enabled foreign interference, with appropriate interdepartmental 
support and collaboration, resources, authorities and a strong public outreach 
mandate. 


xvi 


Recommendation 8 


8.82 The committee recommends the Australian Government address countering 
cyber-enabled foreign interference as part of the 2023-2030 Australian Cyber 
Security Strategy. 


Recommendation 9 


8.85 The committee recommends the Australian Government clarify that 
Magnitsky-style cyber sanctions in the Autonomous Sanctions Act 2011 can be 
used to target cyber-enabled foreign interference actors, via legislative 
amendment if necessary, and ensure it has appropriate, trusted frameworks 
for public attribution. 


Recommendation 10 


8.90 The committee recommends the Australian Government refer the 
National Security Legislation Amendment (Espionage and Foreign Interference) 
Act 2018 to the Parliamentary Joint Committee on Intelligence and Security 
for review, with particular reference to the Act's effectiveness in addressing 
cyber-enabled foreign interference. 


Recommendation 11 


8.94 The committee recommends the Australian Government investigate options 
to identify, prevent and disrupt artificial intelligence (AI)-generated 
disinformation and foreign interference campaigns, in addition to the 
Government's Safe and Responsible AI in Australia consultation process. 


Recommendation 12 


8.97 The committee recommends the Australian Government establish a program 
of vetting appropriate personnel in trusted social media platforms with 
relevant clearances to ensure there is a point of contact who can receive threat 
intelligence briefings. 


Recommendation 13 

8.107 The committee recommends the Australian Government build capacity to 
counter social media interference campaigns by supporting independent 
research. 


Recommendation 14 

8.120 The committee recommends the Australian Government ensure that law 
enforcement agencies, and other relevant bodies such as_ the 
eSafety Commissioner, work with social media platforms to increase public 
awareness of transnational repression. 


xvii 


Recommendation 15 


8.124 The committee recommends the Australian Government empower citizens 
and organisations to make informed, risk-based decisions about their own 
social media use by publishing plain-language education and guidance 
material and regular reports and risk advisories on commonly used social 
media platforms, ensuring this material is accessible for non-English 
speaking citizens. Specific focus should be on protecting communities and 
local groups which are common targets of foreign interference and provide 
pre-emptive information and resources. 


Recommendation 16 


8.130 The committee recommends the Australian Government support 
independent and professional foreign-language journalism by supporting 
journalism training and similar programs, thereby expanding the sources of 
uncensored news for diaspora communities to learn about issues such as 
human rights abuses inside their country of origin. 


Recommendation 17 

8.134 The committee recommends the Australian Government promote the digital 
literacy and the infrastructure of developing countries in the Indo-Pacific 
region that are the targets of malicious information operations by foreign 
authoritarian states. 


xviii 


1.1 


1.2 


1.3 


1.4 


1:5 


at 


2 


Chapter 1 
Introduction and background 


On 24 November 2022, the Senate established the Select Committee on Foreign 
Interference through Social Media (the committee) to inquire and report on the 
following matters: 


(a) the use of social media for purposes that undermine Australia's democracy 
and values, including the spread of misinformation and disinformation; 

(b) responses to mitigate the risk posed to Australia's democracy and values, 
including by the Australian Government and social media platforms; 

(c) international policy responses to cyber-enabled foreign interference and 
misinformation; 

(d) the extent of compliance with existing Australian laws and regulations; 
and 

(e) any other related matters. ! 


Details of the inquiry were made available on the committee's webpage and the 
committee invited organisations, key stakeholders and individuals to provide 
submissions.” 


The committee received 40 submissions, which are listed at Appendix 1 of this 
report. The committee received a private briefing from government agencies on 
20 March 2023 and held the following public hearings for the inquiry: 


e 20 April 2023 Canberra—local and overseas subject matter experts; 

e 21 April 2023 Canberra—local and overseas subject matter experts and 
community-based organisations; 

e 11 July 2023 Canberra—social media companies; and 

e 12July 2023 Canberra— Australian Government departments and agencies. 


A list of the organisations and individuals who attended these public hearings 
can be found in Appendix 2. The public submissions, additional information 
received and Hansard transcripts are available on the committee's website. 


This inquiry continues the work commenced by the Select Committee on 
Foreign Interference through Social Media (2019 select committee) established 
during the 46 Parliament on 5 December 2019. The terms of reference (ToR) for 
the 2019 select committee were the same as for the current inquiry, with the 
exception that interference was defined as including the spread of 


Journals of the Senate, No 22, 24 November 2022, pp. 674-675. 
The committee's webpage is available at: www.aph.gov.au/Parliamentary_ Business/Committees/ 


Senate/Foreign Interference Social Media/ForeignInterference47 


misinformation but not disinformation. This has since been updated in the ToR 
for this inquiry in the 47 Parliament. 


1.6 The 2019 select committee tabled an interim report with seven 
recommendations on 17 December 2021 and a progress report on 21 April 2022. 
Appendix Three outlines those recommendations and any progress made to 
implement them, as of early 2023. 

Acknowledgement 

1.7 The committee thanks all those who have contributed to the inquiry by making 


submissions, providing additional information, and appearing at public 
hearings. 


Report Structure 


1.8 


The report is comprised of eight chapters: 


e This chapter, Chapter 1, outlines the conduct and scope of the inquiry, and 
provides background information on what constitutes foreign interference. 

e Chapter 2 explains how foreign interference manifests in Australia, 
outlining the experiences of people within Australia who have been 
subjected to these campaigns. 

e Chapter 3 discusses international responses to counter foreign interference. 

e Chapter 4 outlines current Australian government responses. 

e Chapter 5 discusses ideas for action proposed by evidence to the inquiry. 

e Chapter 6 discusses platform-based responses and gaps. 

e Chapter 7 outlines how government can better support civil society in its 
responses. 

e Chapter 8 contains the committee comment and recommendations. 


Notes on references 


1.9 References to the Committee Hansard may be references to a proof transcript. 
Page numbers may differ between proof and official transcripts. 

Definitions 

1.10 Readers should be mindful of the following definitions when considering this 
report. 

1.11 Foreign Interference: clandestine activities carried out by, or on behalf of, a 
foreign actor which seek to interfere in decision-making, political discourse or 
other societal norms. Foreign interference is coercive, covert, deceptive or 
corrupting and is contrary to a nation's sovereignty, values and national 
interests. 

1.12 Foreign Influence: overt activities to advocate for particular outcomes or shape 


consideration of issues important to foreign actors. When conducted in an open 
and transparent manner, these activities can contribute positively to public 
debate. 


1.13 


1.14 


1.15 


1.16 


1.17 


1.18 


1.19 


1.20 
1.21 


Foreign Information Manipulation and Interference (FIMI): describes a mostly 
non-illegal pattern of behaviour that threatens or has the potential to negatively 
impact values, procedures, and political processes. Such activity is manipulative 
in character, conducted in an intentional and coordinated manner. Actors of 
such activity can be state or non-state actors, including their proxies inside and 
outside of their own territory. 


Disinformation: False information designed to deliberately mislead and 
influence public opinion or obscure the truth for malicious or deceptive 
purposes. 


Misinformation: False information that is spread due to ignorance, by error or 
mistake with good intentions/without the intent to deceive. 


Coordinated inauthentic behaviour (CIB): where groups of accounts are used 
to work together with the intention to deceive others. CIB can be either 
financially or politically motivated. 


Hybrid warfare: Hybrid warfare is a military strategy which blends 
conventional warfare, irregular warfare, and cyberwarfare with other 
influencing methods, such as fake news, diplomacy, and foreign electoral 
intervention and lawfare—the use of legal systems and institutions to damage 
or delegitimise an opponent. 


Cognitive warfare: The weaponisation of public opinion, by an external entity, 
for the purpose of (1) influencing public and governmental policy and 
(2) destabilizing public institutions. ‘Cognitive’ refers to the manipulation of 
emotional responses to an issue, which then affects the cognitive function of 
decision-making regarding that issue. 


OSINT (open-source intelligence): Publicly available information gathered 
from the Web to inform an investigative or intelligence cycle. 


SOCMINT: OSINT gathered from social media platforms. 
Internet/world wide web is comprised of three layers: 


e Surface web: this layer is only four per cent of the internet and is what most 
people access on a day-to-day basis. It contains all publicly facing websites 
such as Google services, news sites, blogs, social media and commerce sites. 

e Deep web: this layer is around 95 per cent of the internet and involves data 
that cannot be indexed by search engines because it contains sites that 
require logins. For example, sites that contain subscription services, 
banking, medical or government records. 


e Dark web: this is the area of the web containing illegal marketplaces. It must 
be accessed via special browsers such as TOR (The Onion Router) which 
provides anonymity.’ 


What is foreign interference 

1.22 Foreign interference has been an issue of growing global concern in the past 
decade. For example, the European Union (EU) Parliament recently declared it 
was currently 'a target of diverse and aggressive foreign interference 
campaigns'.* 


1.23 In Australia, the most recent annual threat assessment from the 
Director-General of the Australian Security Intelligence Organisation (ASIO) 
stated: 


Australia is facing an unprecedented challenge from espionage and foreign 
interference and I'm not convinced we, as a nation, fully appreciate the 
damage it inflicts on Australia's security, democracy, sovereignty, economy 
and social fabric.® 


1.24 The Department of Home Affairs (Home Affairs) stated that foreign interference 
‘involves foreign powers trying to secretly and improperly interfere in 
Australian society to advance their strategic, political, military, social or 
economic goals, at our expense’.® 


1.25 ASIO submitted that foreign interference 'is particularly insidious in that it uses 
our strengths against us' and noted that perpetrators ‘exploit our values, 
freedoms and trust, thereby undermining our way of life'.7 


3 Definitions developed with reference to a range of sources, including: Department of Home Affairs, 
Submission 16; Select Committee on Foreign Interference through Social Media inquiry 
(46th Parliament), Interim report, p. 4; European Union External Action Service, Ist EEAS Report on 
Foreign Information Manipulation and Interference Threats, February 2023, p. 25; Meta, Submission 32, 
p. 6; Weissman, Nilsson, Palmertz and Thunholm, Hybrid Warfare: Security and Asymmetric Conflict 
in International Relations, Bloomsbury Academic, 2021; Bernal, Carter, Singh, Cao and Madreperla, 


Cognitive warfare: an attack on truth and thought, NATO OTAN, John Hopkins University, Fall 2020, 


p. 3; and, Claire Moravec, ‘The weaponization of social media’, Security Magazine, 14 October 2022. 


4 Special Committee on foreign interference in all democratic processes in the European Union, 
including disinformation (INGE 2), REPORT on foreign interference in all democratic processes in the 
European Union, including disinformation, 2022/2075(INI). 


5 Mike Burgess Director-General of Security, Australian Security Intelligence Organisation, 
Director-General’s Annual Threat Assessment, 21 February 2023. 


6 Department of Home Affairs, Defining foreign interference, www.homeaffairs.gov.au/about- 
us/our-portfolios/national-security/countering-foreign-interference/defining-foreign-interference 
(accessed 14 July 2023) 


Australian Security Intelligence Organisation, Submission 2, p. 2. 


1.26 The Australian Security Intelligence Organisation Act 1979 defines foreign 
interference as: 


e activities relating to Australia that are carried on, by, or on behalf of, are 
directed or subsidised by, or are undertaken in active collaboration with, a 
foreign power, being activities that: 


— are clandestine or deceptive, and: 
— are carried on for intelligence purposes; 
— are carried on for the purpose of affecting political or governmental 
processes; or 
— are otherwise detrimental to the interests of Australia; or 
— involve a threat to any person. 


° A foreign power means: a foreign government; an entity that is directed or 
controlled by a foreign government or governments; or a foreign political 
organisation.’ 


1.27 Dr Seth Kaplan, a United States (US) politics expert and professorial lecturer at 
John Hopkins University’s School of Advanced International Studies, noted the 
practical impact of foreign interference: 

It basically means that, instead of your democracy being a debate among 
people who live in the country, there’s an additional voice that plays a large 
part in the conversation, and that voice is controlled by a foreign 
government that does not have your best interests at heart. I would say that 
that’s the most clear danger. Again, it is basically direct interference in the 
public square—in the information that people are viewing, in the civil 
society organisations, in their ability to organise, in what types of civil 
society organisations might thrive or not thrive.? 


Foreign interference via social media 

1.28 Social media has quickly become a dominant form of communication and 
information sharing, with 4.62 billion people using social media globally. It is 
also fast growing, with nearly half a billion users joining social media in 2021 
alone.” 


1.29 The Australian Human Rights Commission (AHRC) noted that: 


Social media is an integral aspect of everyday life, as it forms the foundation 
of many Australians' communications online. For example, it was estimated 
in February 2022 that some 21.45 million Australians (or 82.7% of the 


8 Australian Security Intelligence Organisation, Submission 2, p. 3. 
? Dr Seth Kaplan, Private capacity, Committee Hansard, 20 April 2023, p. 13. 


10 Claire Moravec, 'The weaponization of social media', Security Magazine, 14 October 2022. 


1.30 


1.31 


1.32 


1.33 


1.34 


population) had active social media accounts, and that 52% of Australians 
use social media as a source of news." 


The AHRC further noted that 'social media can be used for purposes that both 
strengthen or undermine Australia's democracy and values', in that social media 
‘can be used in ways that increase access to information and opportunities for 
the free exchange of ideas, increase the diversity of voice contributing to public 
discussions and allow for broader public participation in our democracy’, but 
on the other hand, ‘social media can also be used in ways that pose a threat to 
democratic processes through social media campaigns that spread 
misinformation and disinformation, undermine trust in public institutions and 
exacerbate divisions within society’. 


Because of its depth and reach into nearly every person's life, social media is 
being increasingly used as a vector for foreign interference. The DISARM 
Foundation has warned that 'the internet is enabling the spread and 
hyper-targeting of disinformation at an unprecedented scale’. 


The Federal Bureau of Investigation (US) has noted that: 


Foreign influence operations—which include covert actions by foreign 
governments to influence U.S. political sentiment or public discourse—are 
not a new problem. But the interconnectedness of the modern world, 
combined with the anonymity of the Internet, have changed the nature of 
the threat."4 


The Australian Strategic Policy Institute (ASPI) submitted that social media 
platforms now form one pillar of the information ecosystem that is 'critical 
infrastructure for the public to make informed decisions in a functioning 
democracy, akin to the criticality of the Australian electrical grid supplying 
power to people's homes’. 


ASPI further noted that the risks of foreign interference through social media 
are exacerbated by the changing news consumption habits, where more and 
more people are using social media platforms as a source of news instead of 
mainstream news outlets, and advised that 'this has implications for the 
Australian Government's ability to regulate and cooperate with social media 


1 Australian Human Rights Commission, Submission 9, p. 4. 
2 Australian Human Rights Commission, Submission 9, p. 3. 


3 DISARM Foundation, What’s this all about, Wwww.disarm.foundation/disinformation 
(accessed 17 May 2023). 


4 Federal Bureau of Investigation, Combating Foreign Influence, www.fbi.gov/investigate/ 
counterintelligence/foreign-influence (accessed 14 July 2023). 


5 Australian Strategic Policy Institute, Submission 13, p. 7. 


platforms that share fewer values in common - such as transparency - and may 
have less power to influence’. 


Misinformation and disinformation 
1.35 A recent EU report analysing foreign interference and FIMI found that: 


e Diplomatic channels are an integral part of FIMI incidents. Russia's 
diplomatic channels regularly serve as enablers of FIMI operations. They 
are deployed across a wide range of topics. China also uses diplomatic 
channels, mostly targeting the US. 

e Impersonation techniques become more sophisticated. Impersonations 
of international and trusted organisations and individuals are used by 
Russian actors particularly to target Ukraine. Print and TV [television] 
media are most often impersonated, with magazines seeing their entire 
style copied. 

e FIMI actor collusion exists but is limited. Official Russian actors were 
involved in 88 analysed FIMI incidents. Chinese actors were involved 
in 17. In at least five cases, both actors engaged jointly. 

e FIMI is multilingual. Incidents do not occur in just one language; content 
is translated and amplified in multiple languages. Incidents featured at 
least 30 languages, 16 of which are EU languages. Russia used a larger 
variety of languages than Chinese actors but 44% of Russian content 
targeted Russian-speaking populations, while 36% targeted 
English-speaking populations. 

e FIMI is mostly intended to distract and distort. Russia (42%) and China 
(56%) mostly intend to direct attention to a different actor or narrative or 
to shift blame ("distract"). Russia attempts to change the framing and 
narrative ("distort") relatively more often (35%) than China (18%). 

e FIMI remains mostly image and video based. The cheap and easy 
production and distribution of image and video material online makes 
these formats still the most commonly used.” 


Social media as part of wider foreign interference 
1.36 Foreign interference through social media does not occur in isolation. ASIO has 
summarised the issue of foreign interference via social media as follows: 
Social media is a vector for foreign interference, not a threat in and of itself. 
However, foreign powers seek to do Australia harm through a variety of 


vectors and capabilities, including social media platforms, often as part of a 
broader campaign and an invariably integrated one.'® 


16 Australian Strategic Policy Institute, Submission 13, p. 6. 


17 European Union External Action Service, 1st EEAS Report on Foreign Information Manipulation and 
Interference Threats, February 2023, p. 5. 


Australian Security Intelligence Organisation, Submission 2, p. 2. 


1.37 


1.38 


Dr William Stoltz, a national security professional and academic, told the 
committee that: 

... any instances of foreign interference that are occurring via social media 

are typically going to be linked to a larger strategic objective and are 


therefore also going to be part of a larger suite of statecraft, both overt and 
covert, that a state would be undertaking.” 


Professor Rory Cormac, from the University of Nottingham, noted that because 
of this, it was important that governments not be 'blinded by the novelty of the 
technology and forget the wider history and the wider concepts that states have 
learned over the years of foreign subversion and interference’.”° 


Foreign interference for economic outcomes 


1.39 


1.40 


1.41 


1.42 


Foreign interference can be conducted by state actors as part of a wider push to 
influence other nation states, but it can also be conducted to seek economic 
outcomes. Ms Lindsay Gorman of the Alliance for Securing Democracy 
explained that: 
We know that China and Russia—especially China—have very active 
espionage campaigns against liberal democracies to steal information, both 


in the traditional national security sense and also in the corporate espionage 
sense.” 


CyberCX submitted that its intelligence has assessed that 'several foreign 
governments have the intent and capability to use social media to harm 
Australia's economic interests, and tactics can include 'social media 
disinformation or data breach operations designed to harm the value or 
reputation of a company, or to pressure a company or its executives to change 
their policies or views'.” 


By way of example, Home Affairs noted reports that Australian mining 
company Lynas Rare Earths was targeted by an information operation seeking 
to undermine efforts to diversify global rare-earth supply chains.” 


The following chapter outlines how foreign interference is manifesting in 
Australia. 


19 Dr William Stoltz, Private capacity, Committee Hansard, 20 April 2023, p. 37. 


20 Professor Rory Cormac, Director, Centre for the Study of Subversion, Unconventional Interventions 
and Terrorism, University of Nottingham, Committee Hansard, 20 April 2023, p. 37. 


21 Ms Lindsay Gorman, Senior Fellow for Emerging Technologies, Alliance for Securing Democracy, 
German Marshall Fund, Committee Hansard, 21 April 2023, p. 13. 


22 CyberCXx, Submission 16, p. 6. 


23 Department of Home Affairs, Submission 1, p. 4. See also CyberCX, Submission 16, p. 4. 


Chapter 2 
Foreign interference in Australia 


Foreign interference in Australia 


2.1 


2.2 


2.3 


1 


2 


Just as foreign interference is a key security concern of nations elsewhere, it is a 
key concern in Australia. The Department of Home Affairs (Home Affairs) 
submitted that: 
Foreign interference and espionage is the principal security concern facing 
Australia. Foreign interference and espionage threaten the things that we 
value most about our country: our social cohesion, our trusted democracy, 
and our freedoms. Australia remains a target of sophisticated and persistent 
foreign interference activities directed towards government, academia, 
industry, the media and our communities. The nature and scale of the threat 
we face is complex, and undermines our sovereignty, values and national 
interests. ! 


The following sections will outline the four key areas of foreign interference that 
are of concern in Australia, two related to the pull of information and two 
related to the push of information. The fears are that social media platforms and 
applications (apps) can be used to: 


e gather intelligence on individuals that can be used to target them; 

e gather behavioural data by population or cohort that can be used to 
improve interference and influence campaigns; 

e harass Australia's diaspora communities; and 

e spread misinformation or disinformation with the intent to: 


— achieve a specific outcome within Australia's political system; 
— manipulate community discourse and understanding about an issue; or 
— spread chaos and seed distrust in Australia's democratic systems. 


Chapter 1 outlined that foreign interference via social media can be part of a 
wider campaign of interference. This has also been experienced in Australia. 
For example, Mrs Kateryna Argyrou, Co-Chair of the Australian Federation of 
Ukrainian Organisations, spoke of Russian interference tactics being used 
against the Ukrainian diaspora community in Australia as always evolving and 
coming from all angles, using social media to support real-world interference. 
Mrs Argyrou described the formation of support groups ostensibly to support 
Ukrainians, but which were in fact established by Russian background people 
who used the groups to gather data on Ukrainians residing in Australia.” 


Department of Home Affairs, Submission 1, p. 3. 


Mrs Kateryna Argyrou, Co-Chair, Australian Federation of Ukrainian Organisations, Committee 
Hansard, 21 April 2023, p. 29. 


10 


2.4 


Badiucao, a Chinese-born Australian artist who is a well-known dissident 
against the Chinese Communist Party (CCP), agreed that social media-based 
interference is often just one of the tactics in a wider interference campaign. 
He told the committee: 


Recently, I also find they are being bolder and aggressive. In February this 
year, I actually got approached by a person who claimed to be a journalist 
of Reuters. Eventually, I found out that this is not the person he claimed to 
be. When I verified with real Reuters journalists, we found out this is not the 
person. It turned out there are three different persons' accounts from 
Telegram channelled into Twitter, pretending to be the entire China bureau 
of Reuters. They are using this fake identity to trick dissidents and the 
Chinese diaspora outside of China, including inside China, to send sensitive 
information about human rights campaigns and other political opinion.’ 


Gathering intelligence on individuals 


2.5 


2.6 


Prior to the prevalence of social media, human intelligence (HUMINT) was 
painstakingly gathered by 'travel, articles, public events, and old fashioned 
boots on the ground surveillance'. However, social media has now become the 
primary source of HUMINT, given the numbers of people posting intimate 
details of their public and professional lives: 


e 59 per cent of people post names or photos of children. 

e 27 per cent of people post names or photos of their partner. 

e 93 per cent of people post employment updates. 

* 36 per cent of people post information about their company job, boss, 
colleagues. 

e 32 per cent of people post updates and photos during business trips. 

e Around 55 per cent of people do not have privacy settings activated on their 
social media.* 


This issue of concern is outlined in greater detail later in this chapter, when 
discussing interference against specific members of diaspora communities in 
Australia, and concerns related to the professional networking site, LinkedIn, is 
discussed in Chapter 6. 


Gathering behavioural data 


2.7 


2.8 


3 


4 


A key concern for the mass gathering of behavioural data via apps such as 
TikTok, is that it enables microtargeting of advertising and influence campaigns, 
which can then be used to engage in foreign interference. 


Internet 2.0 submitted that big data is one of China's stated primary fields for 
strategic competition, and that China sees big data as 'a new opportunity to 
reshape its competitive advantage’. Internet 2.0 further noted that '[e]ffective 


Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 33. 


Claire Moravec, 'The weaponization of social media', Security Magazine, 14 October 2022. 


11 


29 


disinformation campaigns also rely on high quality data to have insight into 
voting patterns.’ 


This issue of concern is discussed in greater detail in Chapter 6, Platforms. 


Harassment of diaspora communities in Australia 


2.10 


2.11 


2.12 


Iran 
2.13 


2.14 


Social media platforms are being used to facilitate the transnational repression 
of individuals and marginalised communities in Australia. The Australian 
Strategic Policy Institute (ASPI) observed that: 
This poses a significant threat to the freedom of Australians, and others 
residing in Australia, to express their opinion and access online spaces ... 
On social media, this includes online trolling, stalking or harassment, and is 
typically conducted by authoritarian states to coerce their citizens and 
others abroad.° 


Four diaspora communities in Australia are currently known to be subject to 
significant surveillance and interference by foreign state actors: Iranians, 
Chinese, Tibetans and Ukrainians. 


The impact of this foreign interference on the lives of individuals cannot be 
overstated. Ms Vicky Xu, a journalist and policy analyst told the committee that: 
... I'm still dealing with death threats. I'm still dealing with repeated hacking 
attempts. Just this week I received a dozen hacking attempts across all of my 
accounts ... I've had to adapt the way I live, my lifestyle, to one that's akin 
to a criminal, I would say. People in democracies, politicians, academics and 
people with good social standing tell me things like I'm going to end up in 
history books, and that all sounds grand, but what about life? I'll just leave 

it at that.” 


There have been many recent media reports of harassment or surveillance of 
Iranians in Australia, specifically targeting dissidents who speak out against the 
current Iranian regime. 


In one case, the mother of a leading Iranian-Australian protester was jailed in 
Tehran and interrogated about her Australian relatives in what her family and 
experts fear is part of a wider attempt to silence Australia’s Iranian 
pro-democracy protesters. Iranian-Australians say they do not feel safe from the 
Iranian regime even inside Australia's borders. Several activists said local 


5 Internet 2.0, Submission 17, p. 3 and 6. 


6 Australian Strategic Policy Institute, Submission 13, p. 3. 


7 Ms Vicky Xu, Senior Fellow, Australian Strategic Policy Institute, Committee Hansard, 21 April 2023, 
p. 35. 


12 


2.15 


2.16 


2.17 


2.18 


2.19 


protests had sometimes turned violent after people suspected of being linked to 
the Iranian regime arrived and filmed them.® 


The Minister for Home Affairs and Minister for Cyber Security advised the 
Australian public in February 2023 that ASIO ‘disrupted the activities of 
individuals who had conducted surveillance in the home of an 
Iranian-Australian’.? 


Mr Peter Murphy, Co-secretary of Australian Supporters of Democracy in Iran, 
told the committee that 'it's very, very clear that in Iran the state controls the 
mainstream media and has also invested heavily in cyberwarfare, 
cybersurveillance and creating its own messaging apps to enable it to monitor 
dissident opinions and communicate its own "information"'.!° 


Mr Murphy further told the committee: 


The basics of our [Australia's] democratic society include freedom of 
association, freedom of speech and freedom of expression, and this family 
in Melbourne has been told to stop talking, stop attending certain meetings 
and stop expressing certain views. It is really a blatant attack on our basic 
rights by a foreign government. 1! 


The Australian Supporters of Democracy in Iran submitted that most 
cybersecurity efforts in Australia do not specifically relate to political 
interference through social media. They argued that 'this is an area of policy and 
governance which is under-developed, including in Australia’. 


A recent expert study commission by the European Parliament noted that ‘Iran 
is among the actors who focus on "laundering disinformation" through 
seemingly legitimate front and proxy media’ and further argued that these 
‘operations will remain untouched by measures targeting fake accounts or 
inauthentic behaviour’. The study recommended a dedicated taskforce, 
fact-checkers and sanctions against malicious actors, but noted that 'sanctions 
would have to be proceeded by appropriate investigations in order to identify 
those who should be sanctioned'.!3 


8 Paul Sakkal, ‘Silencing dissent by threatening family: Iran cracks down on family of Australian 
protester’, The Sydney Morning Herald, 16 January 2023. 


? Minister for Home Affairs and Minister for Cyber Security, Hon Clare O'Neil MP, ‘Foreign 


In 


terference in Australia - ANU address’, 14 February 2023. 


° Mr Peter Murphy, Co-Secretary, Australian Supporters of Democracy in Iran, Committee Hansard, 
21 April 2023, p. 20. 


1 Mr Peter Murphy, Australian Supporters of Democracy in Iran, Committee Hansard, 21 April 2023, 
p. 22. 


2? Australian Supporters of Democracy in Iran, Submission 23, p. 4. 


3 Directorate General for External Policies of the Union, The misuse of social media platforms and other 


communication channels by authoritarian regimes: Lessons learned, December 2021, p. 45. 


13 


Senate inquiry: Human Rights implications of recent violence in Iran 
2.20 The Senate Foreign Affairs, Defence and Trade references committee (FADT 


2.21 


committee) recently tabled a report into politically motivated violence in Iran. 
This inquiry received a significant volume of evidence from effected 
individuals, with a total of nearly 400 submissions. The committee expressed 
concerns at 'reports of threats and intimidation against Australian residents and 
citizens' and noted the ‘high level of concern within the Iranian Australian 
diaspora about potential monitoring of individuals on social media, as well as 
at rallies and protests held in Australia’. 


The FADT committee further noted that Home Affairs and the 
Australian Federal Police advised that reports of such intimidation and threats 
would be investigated where it reached a criminal threshold. The FADT 
committee made three recommendations on this issue: 


e that the responsible Ministers provide an update to the Parliament and the 
Australian public on the government's current assessment of whether 
persons connected to the Islamic Republic of Iran (IRI) regime are 
undertaking such behaviour in Australia; 

e that the Australian Government ensure there is an appropriate level of 
expertise and resourcing in the relevant government departments and 
agencies, including foreign language speakers and community liaison 
officers, available to quickly investigate and assess threats against 
Australians; and 

e that all reports of threats, intimidation, monitoring or surveillance by the 
Iranian community in Australia are followed up, recorded, assessed and 
reported to the lead coordination agency (regardless of whether individual 
reports result in a criminal investigation) to ensure that the government has 
a complete picture of foreign interference efforts by the IRI in Australia. The 
committee further recommended that the relevant agencies report to 
Parliament through the Joint Committee for Intelligence and Security on 
such activities." 


Russia 


2.22 


The committee was told about Russian-backed influence and interference 
campaigns are occurring in Australia. Mrs Kateryna Argyrou of the 
Australian Federation of Ukrainian Organisations, told the committee 'we have 
many members of our community that have been targeted by either the Russian 
community or the Russian consulate here’. Mrs Argyrou said the targeting was: 


Senate Foreign Affairs, Defence and Trade References Committee, Human Rights implications of 


recent violence in Iran, p. 49. 


Senate Foreign Affairs, Defence and Trade References Committee, Human Rights implications of 


recent violence in Iran, pp. 38-51. 


14 


... quite varied, anything from direct death threats through social media, 
mostly coming through Telegram and Facebook where certain people, 
especially community leaders, are targeted in the most vile way. They 
basically describe how they would be executed, beheaded, where their head 
is going to end up and so on and so forth. It's very confronting." 


2.23 Mrs Argyrou further stated that community concerns around COVID-19 have 
been used as a tactic for influence campaigns: 


They've found a very innovative and interesting way to do that, where they 
target different subgroups in Australia to try to influence opinion and 
perception. For example, through ... the Russian consulate and Russian 
agents in Australia they have been very successful in infiltrating the antivax 
movement. First, they learn about the ideals and aims of a certain 
movement. They share those ideals and views, and they quickly become 
leaders of that and through that they place typical Russian narratives and 
propaganda. They have been very successful in infiltrating that antivax 
movement here in Australia, and that's just one example.!” 


China 
2.24 The committee received a great deal of evidence of the CCP engaging in 
interference in Australia, both via social media and in real-world events. 


2.25 Badiucao, a Chinese-born Australian dissident artist told the committee: 


I have been receiving death threats almost on a daily basis. That has just 
been a burden on me every day. The Chinese government know that the 
only way that they can stop dissidents overseas from talking about the 
important human rights issues is by launching character assassination 
campaigns.'® 


2.26 Badiucao further told the committee with regard to WeChat: 


... WeChat has become this very toxic headquarters for misinformation and 
propaganda for the Chinese government, but at the same time for users, no 
matter whether you’re inside China or outside China in Australia, the rate 
for free speech to survive is zero. 


2.27 Ms Vicky Xu, a journalist and policy analyst told the committee that: 


... the Chinese government has been attempting to silence, intimidate and 
harass me ... Because of my reporting on [Hong Kong protests] — whether 
that's orchestrated by someone or whether that's just voluntary sort of anger 
from the people, I don't know—a large online social harassment campaign 


Mrs Kateryna Argyrou, Australian Federation of Ukrainian Organisations, Committee Hansard, 
21 April 2023, pp. 27-28. 


Mrs Kateryna Argyrou, Australian Federation of Ukrainian Organisations, Committee Hansard, 
21 April 2023, p. 27. 


8 Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 33. 


Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 35. 


15 


2.28 


2.29 


Tibet 
2.30 


2.31 


2.32 


occurred on the platform called Weibo. It had such an impact on my family 
life that I became estranged from my father.” 


Ms Xu told the committee that social media played a large role in this character 
assassination ‘because there are hundreds of accounts pumping out content that 
goes across the entirety of the Chinese internet, so from WeChat and Weibo to 
the Chinese version of Quora, which is Zhihu, and to the video platforms'.?! 


Dr Seth Kaplan noted the dangers that Chinese social media platforms and apps 
pose to the Australian-Chinese community: 
. the Chinese diaspora in Australia, the Chinese Australians, are a 
vulnerable community because of how their information is being managed, 
and that information prevents many voices from being heard. It prevents 
many civic activities or civil society organisations forming and/or 
developing. It creates tensions within the community because only certain 
voices, which could be more extreme on the left or right or could simply be 
saying very negative [things].” 


Mr Kalsang Tsering, President of the Australian Tibetan Community 
Association (Tibetan Association), told the committee of the plight of 
Tibetan-Australians being monitored by the CCP in Australia: 

There are about 3,000 Tibetans all over Australia. Tibetan communities have 

been persecuted, and we are not able to freely contact our families back in 

Tibet. Most of the Tibetans in Australia are former political prisoners; or 

their parents or siblings are former political prisoners. Almost everyone, 


90 per cent of us, have families back in Tibet, and we cannot freely 
communicate with them. 


The Tibetan Association submitted a range of alleged human rights abuses by 
the CCP against Tibetan-heritage people in Australia, including instances of 
surveillance, interference, and repression of freedom of expression, association, 
and the right to protest. The association also claimed that bots are used to spread 
CCP information, misinformation and disinformation, disseminate disunity, as 
well as to attack posts in support of Tibet. 


The Tibet Association claimed that some of these actions have been taken 
through social media applications, including WhatsApp, Twitter, Facebook, and 
WeChat (used by Tibetans and Chinese overseas and in Australia) and through 
phone calls and messages. 


2 Ms Vicky Xu, Australian Strategic Policy Institute, Committee Hansard, 21 April 2023, p. 34. 


21 Ms Vicky Xu, Australian Strategic Policy Institute, Committee Hansard, 21 April 2023, p. 34. 


2 Dr 


23 


Seth Kaplan, Private capacity, Committee Hansard, 20 April 2023, p. 15. 


Mr Kalsang Tsering, President, Australian Tibetan Community Association, Committee Hansard, 


21 April 2023, p. 24. 


16 


2.33 The Tibetan Association discussed the action taken against Tibetans and their 


families including harassment, fear, intimidation, death threats and actions 
against family in Tibet. It also claimed that Tibetan community members in 
Australia have become increasingly suspicious and paranoid of each other as a 
result of this work. Mr Tsering stressed this impact directly to the committee, 
stating: 


It is a very big thing for us to communicate freely, because we were born in 
Tibet and came to Australia as a second home. We want to speak about the 
atrocities and the human rights violations in Tibet, but we cannot speak 
freely. Still, we feel that it's our duty, in a free country like Australia, to speak 
about what is happening inside Tibet. As we do that, the Chinese 
government even tries to go through our phones or laptops and tries to get 
information about us, and then they try to persecute, question or detain our 
families back home.” 


China —global concerns 


2.34 Information considered by the committee strongly suggests that the Australian 


2.35 


24 


examples above are not happening in isolation, and are not only happening to 
diaspora communities. They are occurring as part of a global interference and 
influence campaign by the CCP, that has been decades in the making and has 
the potential to inflict seismic shifts in geopolitical stability. 


A recent joint address was made by the heads of Security Service MI5 
(United Kingdom) and the Federal Bureau of Investigation (United States). It 
was the first time the heads of those agencies had shared a public platform, and 
they came together 'to send the clearest signal we can on a massive, shared 
challenge: China’. The address made the following key points: 


e The CCP is covertly applying pressure across the globe. Rather than lone 
actors it is a coordinated campaign on a grand scale, and involves planned, 
professional activity to conduct a strategic contest across decades. 

e The CCP adopts a whole-of-state approach in which businesses and 
individuals are forced by law to cooperate with the Party. 

e President Xi said that in areas of core technology where it would otherwise 
be impossible for China to catch up with the West by 2050, they 'must 
research asymmetrical steps to catch up and overtake’. 

¢ The CCP doesn't just use intelligence officers posing as diplomats in the 
classic fashion. Privileged information is gathered on multiple channels, in 
what is sometimes referred to as the 'thousand grains of sand’ strategy. 

e The Chinese intelligence services, or bodies within the CCP itself—such as 
its United Front Work Department—are mounting patient, well-funded, 
deceptive campaigns to buy and exert influence. 


Mr Kalsang Tsering, Australian Tibetan Community Association, Committee Hansard, 21 April 2023, 


p. 24. 


17 


e Countering state threats needs a profound whole-of-system response, 
bringing together not just the national security community but counterparts 
in economic and social policy, in industry, in academia.” 


2.36 Inits February 2023 report on foreign interference, the European Union External 


Action Service identified the CCP as a: 


.. multifaceted FIMI [foreign information manipulation and interference] 
actor with an arsenal that is diverse and includes various tactics. Its activities 
range from benign — public diplomacy - to clearly illegitimate — intimidation 
and harassment of critical voices with the aim of suppressing information 
also outside of its borders.” 


2.37 The report outlined that China has been seen using its own state-controlled 


media and economic leverage over other media outlets to influence media 
coverage in its own interests, while simultaneously suppressing critical stories 
using 'a wide range of often covert tactics, including intimidating and harassing 
individuals, also targeting overseas Chinese communities’ .”” 


2.38 An ASPI report into cyber-enabled foreign interference found that: 


The Chinese Communist Party (CCP) has invested US$6.6 billion into its 
global media presence since 2009. It has run covert information operations 
on Silicon Valley social media platforms since at least 2017. The party invests 
in global data collection on a massive scale, and its external propaganda is 
increasingly precisely targeted to granular international audience 
segments.?8 


2.39 The ASPI report pointed to statements by Chinese President Xi Jinping that 


clearly outlined this intent and noted that 'the CCP is strategically and 
deliberately building an international-facing propaganda system that's 
designed to reshape the international order'.” 


2.40 Ms Lindsay Gorman of the Alliance for Securing Democracy noted the 


25 


26 


27 


28 


29 


increasing use of social media by the CCP to achieve these strategic objectives. 
Ms Gorman told the committee: 


... over the last five years, PRC [People's Republic of China] diplomats and 
state media outlets have flocked to social media to spread China's message 


Security Service MI5, Joint Address by MI5 and FBI Heads, 6 July 2022, 
www.mid.gov.uk/news/speech-by-mi5-and-fbi (accessed 14 July 2023) 


European Union External Action Service, 1st EEAS Report on Foreign Information Manipulation and 
Interference Threats, February 2023, p. 10. 


European Union External Action Service, 1st EEAS Report on Foreign Information Manipulation and 
Interference Threats, p. 10. 


Ms Danielle Cave and Dr Jacob Wallis, 'Cyber-enabled foreign interference’, Strategic Insights, 
November 2022, p. 20. 


Ms Danielle Cave and Dr Jacob Wallis, 'Cyber-enabled foreign interference’, Strategic Insights, 
November 2022, pp. 20-21. 


18 


to the world, increase its discourse power, denigrate the United States and 
the international world order, and position itself as an alternative 
democracy.” 


2.41 Mr Fergus Ryan of ASPI similarly told the committee: 


2.42 


2.43 


The Chinese Communist Party and propaganda officials see a unique 
opportunity in the world at the moment, where the internet has disrupted 
traditional media. They see social media as an outlet that they can use to 
close the gap when it comes to China's soft power versus the West's soft 
power. These activities have been taking place on Facebook, on Twitter and 
on YouTube, and, as you said, there have been efforts to identify that activity 
that's taking place.*! 


Internet 2.0 described how authoritarian regimes, including China, 'know the 


value of the data, and have moved to collect it on us and limit our access to it in 
their social media domain’ and 'conduct mass surveillance through social media 
within their own borders’. Internet 2.0 went further to state that applications 
such regimes build are purpose-built for surveillance and when they ‘export 
these business models to our social media environments the legacy of this 
surveillance culture permeates’. 


Ms Yaqiu Wang, a Senior China Researcher with Human Rights Watch told the 


committee that China broadens its intelligence gathering reach by coercing 


private companies and using them as tools for political purposes: 


The CCP has a record of compelling domestic and foreign companies to toe 
the party line and of punishing those who fail to sufficiently do so. It has 
forcefully disappeared a score of business executives under murky 
circumstances, a practice that has only increased in recent years under 
President Xi Jinping... this sends a clear message to business leaders in 
China that the price of opposing, or even appearing to oppose, the CCP can 
be extraordinarily steep. 


2.44 Ms Shanthi Kalathil, a former advisor on the United States 
National Security Council, told the committee of relevant Chinese laws: 


30 


31 


32 


33 


There are a number of data laws that are relevant to this issue, including the 
2015 National Security Law, the 2017 National Intelligence Law, the 2017 
national Cybersecurity Law and the Data Security Law. The lack of a 


(US) 


Ms Lindsay Gorman, Senior Fellow for Emerging Technologies, Alliance for Securing Democracy, 
German Marshall Fund, Committee Hansard, 21 April 2023, p. 8. 


Mr Fergus Ryan, Analyst, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, 


p. 20. 


Internet 2.0, Submission 17, p. 5. 


Ms Yaqiu Wang, Senior China Researcher, Human Rights Watch, Committee Hansard, 21 April 2023, 


p. 1. 


19 


2.45 


meaningful barrier between private enterprise and the demands of the party 
state is less a technical or legal issue than a political issue.*4 


Meta also provided commentary on changes in approach and an overall 
escalation of coordinated inauthentic behaviour (CIB) originating from China: 


... we have seen quite a shift in tactics and approach by China based actors 
over the past seven months or so. Fifty per cent of the China-originating CIB 
networks we have actioned in the last four years we've taken down in the 
last seven months. We are seeing a whole range of new tactics evolving, such 
as operations that are linked to troll farms; attempts to co-opt journalists, 
NGOs [non-government organisations] or other respected third parties; and 
attempts to work through PR [public relations] firms.” 


Case study: Mr Kenny Chiu 


2.46 


2.47 


2.48 


2.49 


According to an independent thinktank, the Council on Foreign Relations, 
China has pursued a pattern of influence operations in the Pacific Rim to shift 
narratives toward China's points of view, promote pro-China politicians, or 
sometimes just to sow chaos and falsehood. US law enforcement authorities 
warned about such interference in the 2022 midterm elections and both Google 
and Meta's cybersecurity arms have warned of Chinese online interference in 
the midterms.* 


Raising similar concerns about north American election meddling, 
Canadian Security Intelligence Service documents revealed that China had 
employed a sophisticated strategy to defeat Conservative Party politicians 
considered to be unfriendly to Beijing in the 2021 federal election in Canada. The 
tactics included disinformation campaigns, undeclared cash donations and the 
use of international Chinese students studying in Canada, as campaign 
volunteers to support preferred Liberal Party candidates.*” 


The committee heard directly from Mr Kenny Chiu, a former Canadian member 
of parliament who said China's alleged election meddling is the reason he lost 
his seat in the 2021 Canadian federal election. 


In 2021, Mr Chui introduced a private members bill which proposed a 
Foreign Influence Registry to require ‘individuals acting on behalf of a foreign 
principal to file a return when they undertake specific actions with respect to 
public office holders'. The purpose of the bill became the target of a 
misinformation campaign. Mr Chiu also had a background in parliament of 


34 Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 2. 


35 Mr Josh Machin, Head of Public Policy, Australia, Meta, Committee Hansard, 11 July 2023, p. 3. 


36 Joshua Kurlantzick, 'China's Growing Interference in Domestic Politics: Globally and in the United 
States’, Council on Foreign Relations, 1 November 2022. 


37 Robert Fife and Steven Chase, 'CSIS documents reveal Chinese strategy to influence Canada's 2021 


e 


lection', The Globe and Mail, 22 February 2023. 


20 


2.50 


2.51 


2.52 


advocating for Hong Kong and democracy, and criticising Beijing's violations of 
human rights, as well as urging the Canadian government to impose sanctions 
on China. 


Mr Chiu reported that during the 2021 federal campaign, he discovered WeChat 
stories circulating which claimed that his private members bill would put 
Chinese-Canadians in danger. Mr Chui alleged efforts to oust candidates seen 
as unfriendly to Beijing, and stated he was targeted by pre-election 
disinformation on Chinese-language social media.” 


Mr Chiu told the committee: 


It started before the election, and during the election we started seeing 
authoritative articles being written and circulated among the WeChat 
community which both attacked my then leader, Mr Erin O'Toole, and 
specifically also used my private member's bill to attack me. The articles 
claimed that we were anti-Chinese, that we were Chinese haters and that 
therefore we must be opposed. They said that should I get re-elected again, 
my bill would somehow automatically be passed, and all Chinese in Canada 
would be subject to unimaginable Chinese exclusion and persecution. This 
disinformation was activated soon after the election started and came with 
a ferocity that, frankly speaking, was not what I had anticipated or expected, 
so we were caught unprepared.“ 


Media reporting also appears to suggest the interference campaign went 
unnoticed by the body established by the Canadian government to 'monitor 
threats to federal elections’. The Security and Intelligence Threats to Elections 
Taskforce is reported to have issued no public warnings about any campaigns 
and advised the Prime Minister that it had found no evidence of interference, 
reporting to parliament that it had 'determined that the integrity of our elections 
was not compromised in 2019 or 2021'.“1 However, it appears that since 2021 
foreign interference threats to democratic elections in Canada have only 
grown.” 


Interference in Australian politics 


2.53 


Internet 2.0 submitted that authoritarian regimes seek to interfere in elections 
within liberal democracies not just to promote preferred candidates, but also 


38 Sze-Fung Lee and Benjamin Fung, ‘Misinformation and Chinese interference in Canada's affairs’, 


Policy Options, 4 January 2022. 


3 Chuck Chiang, 'Canada has become "open market" for foreign interference in elections, former 
Conservative MP says’, The Canadian Press, 18 February 2023. 


4 Mr Kenny Chiu, Private capacity, Committee Hansard, 21 April 2023, p. 15. 


41 Robert Fife and Steven Chase, 'CSIS documents reveal Chinese strategy to influence Canada's 2021 


e 


lection', The Globe and Mail, 22 February 2023. 


42 See, for example: Steven Chase, 'A timeline of China's alleged interference in recent Canadian 


e 


lections', The Globe and Mail, 9 March 2023 (accessed 26 July 2023). 


21 


2.54 


2.55 


2.56 


2.57 


simply to reduce confidence of the population in the true results of elections. 
It stated that by 'conducting divisive campaigns, they seek to divide our 
societies, to weaken us, and to fracture our uniting values'.* 


CyberCX agreed, noting that ‘disinformation and misinformation need not 
change the outcome of an election, but merely raise the spectre of illegitimacy'.“ 


During the Australian Security Intelligence Organisation (ASIO) annual threat 
assessment in 2022, the Director-General advised: 
. espionage and foreign interference has supplanted terrorism as our 
principal security concern ... The threat is pervasive, multifaceted and, if left 


unchecked, could do serious damage to our sovereignty, values 
and national interest. 


I can confirm that ASIO recently detected and disrupted a foreign 
interference plot in the lead-up to an election in Australia. 


The Director-General provided details of the attempted foreign interference. 
A wealthy individual with direct and deep connections to a foreign government 
and its intelligence agencies hired and financed an employee to identify 
candidates likely to run in the election who either supported the interests of the 
foreign government or who were assessed as vulnerable to inducements and 
cultivation. These candidates were then supported through financial donations 
and promoted in positive media stories in Australian foreign language media. 
The purported aim was to exploit successful candidates’ sense of indebtedness 
and to manipulate them to the advantage of the foreign government. 


ASIO intervened and harm was avoided. However, ASIO suggested a scenario 
of possible outcomes from a successful interference of this nature: 


Some of the candidates get elected. The puppeteer's employee then 
recommends they hire certain other associates as political staffers. These 
people are also agents or proxies of the foreign government, and will try to 
influence the politician, shape decision-making and help identify other 
political figures who can be influenced and recruited. Down the track, the 
new parliamentarians might be asked for information about the party's 
position on defence policy, human rights, foreign investment or trade. This 
information will be sent to the foreign power without the knowledge of the 
parliamentarian. At some point, the politicians might be prevailed upon to 
vote a particular way on a contentious issue, or lobby colleagues to vote a 
certain way.“ 


43 Internet 2.0, Submission 17, p. 6. 


44 CyberCX, Submission 16, p. 2. 


* Australian Security Intelligence Organisation, Director-General’s Annual Threat Assessment 
9 February 2022. 


Tactics 

2.58 The following section outlines some of the key tactics used in foreign 
interference through social media. Actions being taken to address these are 
described in Chapter 6, which looks in-depth at social media platforms. 


Misinformation and disinformation 

2.59 Misinformation and disinformation are key concerns in this space, however 
ASIO noted that they are distinguished from each other on the basis of intent: 
misinformation is false or misleading content spread due to ignorance or by 
mistake, while disinformation also involves false or misleading content with an 
intention to cause harm or deceive.“ 


Box 2.1 Department of Foreign Affairs and Trade, Our Work: 
Disinformation & Misinformation 

The increasing ubiquity of cyberspace and social media platforms as a 
source of information and for personal engagement on a wide range of 
social and community issues has made them a key venue for the 
dissemination and amplification of disinformation and misinformation. 


Disinformation may be used as a tool for foreign interference. Foreign actors 
continue to spread disinformation to serve their own strategic interests and 
to undermine public trust in democratic institutions and confidence in 
official messaging, disrupt the proper functioning of open media, or 
undermine social cohesion. 


Recent electoral processes around the world have shown that digital 
disinformation campaigns have low barriers to entry, and that malicious 
actors have effectively hijacked public discourse to influence communities 
and broader public opinion on matters of significant importance. 
Unwittingly, platforms designed to promote openness have been 
misappropriated to promulgate and amplify disinformation and 
misinformation, sow division and mistrust, and ultimately pervert public 
discourse. 


Malicious use of critical technologies is increasingly occurring to amplify 
these campaigns. This includes 'bots' that drown out legitimate online 
debate, data-driven technologies that enable malicious or harmful 
micro-targeting of susceptible and/or influential audiences, and machine 
learning-enabled ‘deep fakes' that spread disinformation. 


Disinformation should be differentiated from foreign influence. All 
governments can seek to influence discussions on issues of importance. 


When conducted in an open and transparent manner, foreign influence can 


4° Australian Security Intelligence Organisation, Submission 2, p. 3. 


2.60 


2.61 


2.62 


contribute positively to public debate and form a legitimate part of 
international engagement.” 


As outlined above, disinformation can be spread by foreign state actors for the 


purposes of influencing election outcomes, influencing decision-making, 
targeting diaspora communities or simply to spread chaos and create dissent. 


Australians are most likely to see disinformation on larger digital platforms, like 
Facebook and Twitter. However, smaller private messaging apps and 
alternative social media services are also increasingly used to spread 
disinformation or conspiracies due to their less restrictive content moderation 
policies.“ Because foreign interference by social media takes place on commonly 
used and trusted platforms, it is hard for laypeople to detect when going about 
their business online. 


The following sections discuss how misinformation and disinformation is 
spread online. 


Algorithms 


2.63 


2.64 


2.65 


The use of algorithms on social media is ubiquitous. These programs run in the 
background of platforms like Facebook, Twitter and YouTube, analysing what 
material a user is interested in and tailoring their social media feed to gather as 
much of the user's time and attention as possible. While what appears on a social 
media feed can feel ‘natural’, these recommender systems and algorithms can 
actually be used to not only identify people's interests but also manipulate their 
emotions. 


The eSafety Commissioner recently developed a position statement on 
recommender systems and algorithms which stated that 'while recommender 
systems and algorithms have positive uses, they can also present an array of 
risks to users' one of which is to ‘amplify harmful and extreme content, 
particularly when used by platforms whose content feeds are driven by user 
engagement’. The eSafety Commissioner further noted that this can normalise 
‘prejudice and hate and distrust in public institutions’ and may also ‘contribute 
to radicalisation towards terrorism, violent extremism, and provide users with 
avenues to find associated groups'.” 


In a submission to the inquiry held in the 46th Parliament, 
Responsible Technology Australia described how these algorithms were 


47 Department of Foreign Affairs and Trade, Our Work: Disinformation & Misinformation, 
www.internationalcybertech.gov.au/our-work/security/disintormation-misinformation 


(accessed 17 January 2023. 


48 Australian Communications and Media Authority, A report to government on the adequacy of digital 
platforms’ disinformation and news quality measures, June 2021, p. 1. 


2 eSafety Commissioner, Submission 10, p. 1. 


24 


initially developed to sell advertisements, but now have been found to often 
have the unintended effect of promoting extreme and inflammatory material: 


As the primary aim of these platforms is to maximise user time spent on 
them (to increase their advertising revenue potential), the algorithms are 
incentivised to serve material that is calculated to engage users more. This 
content tends to be more extremist or sensationalist or untrue - as it has been 
shown to be more captivating. This opens the door for foreign agents to seed 
inflammatory and sensational content that users engage with out of outrage 
or support, and is then amplified by the algorithms which see all 
engagement as warranting amplification - regardless of the nature of the 
content.°? 


Micro-targeting 
2.66 While the use of algorithms described above could be described as a 'normal' 


part of the experience of being on social media platforms, micro-targeting is the 
weaponisation of the social media environment to further the goals of various 
actors — corporate, international or even malicious actors. 
Responsible Technology Australia described the practice as: 


Targeted Advertising | The unfettered approach to data collection has 
amassed history's largest data sets, allowing advertisers to push beyond 
normal constraints to deliver direct and granular targeting of consumers. 
This microtargeting often uses key emotional trigger points and personal 
characteristics to drive outcomes, which malicious actors can easily exploit 
to sow distrust, fear and polarisation.*! 


2.67 The Joint Select Committee on Electoral Matters’ Report on the Conduct of the 2016 


Federal Election described the phenomenon as ‘dark advertising’, which ‘allows 
groups and companies to target specific individuals or groups (micro-targeting), 
with the goal of shifting their opinions. It is different from normal advertising 
because it will be seen by only the intended recipient.’ 


Bots 
2.68 A common method of foreign interference and/or influence on social media is 


50 


51 


52 


the use of ‘bots’. Bots (short for 'robots’) are artificial social media accounts that 
mimic the behaviour of real users, spreading misinformation or otherwise 
enacting whatever function they have been designed to carry out. Bots are: 

. algorithmically-driven computer programmes designed to carry out 


specific tasks online, such as analysing and scraping data. Some are created 
for political purposes, such as automatically posting content, increasing 


Responsible Technology Australia, Submission 17: Foreign Interference through Social Media inquiry 
(46th Parliament), p. 2. 


Responsible Technology Australia, Submission 17: Foreign Interference through Social Media inquiry 
(46th Parliament), p. 2. 


Joint Standing Committee on Electoral Matters, Report on the conduct of the 2016 federal election and 
matters related thereto, November 2018, p. 176. 


25 


2.69 


2.70 


follower numbers, supporting political campaigns, or spreading 
misinformation and disinformation.™ 


Bots can be difficult to identify and remove, and are sometimes sufficiently 
‘intelligent’ to interact with accounts operated by real people. These bots can be 
used to spread rumours, promote individuals and otherwise rapidly spread 
misinformation and disinformation online. 


A related online phenomenon is a 'rumour cascade’, which bots can assist in 
propagating. A rumour cascade begins when a singular user makes an assertion, 
leading to other propagating the rumour and retweeting it. Researchers have 
found that 'false news spreads more pervasively than the truth online’, which is 
still mainly perpetrated by human users, as opposed to bots.™ 


Troll farms 


2.71 


212 


Troll farms (or factories) create multiple fake social media profiles to conduct 
disinformation propaganda activities on the Internet, usually focused on the 
political or economic sphere, for example, attacking political opponents or other 
action indicated by the ordering party. Troll farms achieve their goals using, 
among other things, fake news and hate speech.” 


The committee was told of that in April 2023, US prosecutors charged 34 officers 
of China's Ministry of Public Security with operating a troll farm to attack 
Chinese dissidents, sow division and disseminate disinformation. 
The committee heard that prosecutors 'allege that the officers were part of an 
elite task force called the 912 Special Project Working Group and that the group 
created thousands of fake profiles on social media sites, including Twitter, and 
spread propaganda about topics like human rights in Hong Kong and the 
Xinjiang region'.* 


Content farms 


219 


Content farms use similar tactics as troll farms, by creating multiple fake 'news' 
sites that appear to be separate entities but are in fact jointly operated and 
coordinated. They are profit driven to generate traffic and advertising revenue 
and usually distribute entertainment-based content, 'articles about politics and 
current affairs are also common, especially if news events are sensational or high 


53 House of Commons (United Kingdom), Digital, Culture, Media and Sport Committee, 


Disinformation and ‘fake news’: Interim report, 29 July 2018, p. 19. 


°4 Soroush Vosoughi, Deb Roy and Sinan Aral, ‘Ihe spread of true and false news online’, Science, 
9 March 2018, Volume 359: 6380, pp. 1146-1151. 


5 North Atlantic Treaty Organization (NATO), Media — (Dis)Information — Security, pp. 1-2. 


5 Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 2. 


26 


profile’. Content farms can then be ‘leveraged by state actors to disseminate 
propaganda or manipulate how the reporting of events is framed'.%” 


Emerging Tactics 

2.74 Three new tactics that have the potential to exponentially increase foreign 
interference through social media are now emerging: the establishment of 
companies that offer fee-based interference services; the development of 
artificial intelligence; and, the increasing decentralisation of social media apps. 


Foreign Interference as a fee-service 

2.75 A report by the Oxford Internet Institute in early 2021 highlighted the existence 
of disinformation-as-a-service. Then in 2023, another report highlighted the 
emergence of foreign interference-as-a-service. 


2.76 In early 2021 the Oxford Internet Institute reported that disinformation had 
become 'a common strategy of cyber manipulation’ and reported that of the 
‘organised social media manipulation campaigns’ found to operate in 
81 countries, 'more than 76 of these campaigns deployed disinformation as part 
of political communication’. One of the report's authors noted that: 

Our 2020 report highlights the way in which government agencies, political 
parties and private firms continue to use social media to spread political 
propaganda, polluting the digital information ecosystem and suppressing 
freedom of speech and freedom of the press. A large part of this activity has 


become professionalized, with private firms offering disinformation-for- 
hire services.** 


2.77 The Oxford Internet Institute's researchers found: 


e Private 'strategic communications’ firms are playing an increasing role in 
spreading computational propaganda, with researchers identifying state 
actors working with such firms in 48 countries. 

e Almost $60 million has been spent on firms who use bots and amplification 
strategies to create the impression of trending political messaging. 

e Social media has become a major battleground, with firms such as Facebook 
and Twitter taking steps to combat 'cyber troops', while some $10 million 
has been spent on social media political advertisements. The platforms 
removed more than 317 000 accounts and pages from 'cyber troops' actors 
between January 2019 and November 2020.” 


5 Dr Wallis, Bogle, Zhang, Mansour, Niven, Ho, Liu, Dr Ong, and Dr Tapsell, ‘Influence for hire’, 
Strategic Insights, Policy Brief Report No. 48/2021, 10 August 2021, p. 17. 


58 Oxford Internet Institute, 'Social media manipulation by political actors now an industrial scale 
problem prevalent in over 80 countries — annual Oxford report’, Media release, 13 January 2021. 


5 Oxford Internet Institute, ‘Social media manipulation by political actors now an industrial scale 


problem prevalent in over 80 countries — annual Oxford report’, Media release, 13 January 2021. 


27 


2.78 In early 2023 a global group of reporters working together uncovered an outfit— 
referred to in reporting as 'Team Jorge'—that provided hacking and 
disinformation services and had allegedly actively interfered in the electoral 
processes of 33 elections around the world. The investigation and subsequent 
reporting on the scale and scope of the group's activities highlighted that 
foreign-interference-as-a service had well and truly arrived. 


2.79 An article reporting on the group's activities observed that 'in the past, online 
disinformation campaigns appeared to work in isolation’, but Team Jorge 
operated differently: 


What's so powerful about this example is that they're not just doing the 
disinformation, they're also involved in 'on the ground’ operations. That's a 
really dangerous combination ... As an example: reporters were able to 
identify a fake protest staged outside a company headquarters in London 
where masked protesters filmed themselves waving placards — a stunt that 
was then circulated on social media. 


Artificial intelligence 
2.80 Artificial intelligence (AI) is expected to have an exponential impact on foreign 
interference and disinformation campaigns. Internet 2.0 submitted: 


Artificial intelligence will enable disinformation campaigns as it 
exponentially increases the computation and distribution of high quality 
information ... The implications of artificial intelligence, if it is not regulated 
in its use within journalism, elections, and the media, are that our 
authoritarian adversaries will have the advantage in the information 
domain.°! 


2.81 Ms Shanti Kalathil noted that foreign interference 'is about to take a significant 
turn into the unknown anyway, with the advent of generative AI and other 
advances’. Ms Kalathil advised that: 

. we are behind the curve in equipping society's populations and 
educational institutions and other key components of civil society with the 
knowledge and resilience to pass information in this age. There's no easy 
solution to this issue, but at a minimum we must be better prepared to 
confront even more potent forms of information manipulation than what we 
have already encountered.” 


2.82 Ms Lindsay Gorman of the Alliance for Securing Democracy outlined the 
dangers that AI presents for foreign interference: 


Deepfake images, video and text can enable automated propaganda. The 
rise of content that looks plausible but is not necessarily true also runs the 
risk of undermining broader trust in the information environment, which is 


60 Archie Bland, "Thursday briefing: The secret disinformation group who claim to influence elections 
worldwide’, The Guardian, 16 February 2023 (accessed 26 July 2023). 


61 Internet 2.0, Submission 17, p. 6. 


62 Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 2. 


28 


2.83 


2.84 


2.85 


critical for quality information to flourish in democracies. As democracies 
contemplate regulation on AI, restoring trust in the information 
environment and guarding against authoritarian information manipulation 
should be at the forefront of these conversations. 


Mr David Robinson of Internet 2.0 argued that AI ‘is increasing the effectiveness 
of influence and disinformation campaigns against elections’ and that when 
combined with high quality data 'we cannot guarantee we can defend ourselves 
and we will not be able to reverse the loss of trust our system will suffer’. 


Mr Robinson further noted the impact that AI will have on democracy: 


Social media is so important in elections because people make decisions 
based on what the group is saying or doing, and government makes 
decisions in its normal running based on what it thinks the population 
wants. [However] a social media platform with AI and botnets can create 
hundreds of thousands of accounts and talk about the same issue. That 
influences what you as lawmakers and politicians and what the population 
do and say to each other. I think AI is very dangerous, and if we don't have 
laws to regulate how it acts on social media—about talking about elections, 
for example—I think we're running out of time, to be honest. I think it's the 
most dangerous thing.® 


The Australian Signals Directorate similarly advised the committee that AI 
poses risks through its ability to 'speed up the capacity' of cyber-based attacks.” 
Home Affairs noted that the Department of Industry is the coordinating body 
for the current project which is 'forming a whole-of-government position on the 
opportunities and risks associated with AI’, with Home Affairs providing the 
‘national security policy advice informing that decision-making’ including by 
‘partnering with research institutions to understand the policy parameters and 
techniques that currently exist in perpetrating or proliferating the threat'.” 


Meta Threads and decentralisation 


2.86 


Launched on 5 July 2023 by Meta, Threads is touted as a decentralised version 
of Twitter and signed up 30 million users in its first day. A key aspect of 
decentralisation is the ability for users to host their own instances or servers, 
giving greater control over their data (including apps Lens Protocol, Mastodon 
and Steemit). While Threads does not currently offer this option, technology 


63 Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 9. 


& Mr David Robinson, Director, Internet 2.0, Committee Hansard, 20 April 2023, p. 31. 


& Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 35. 


6 Ms Abigail Bradshaw, Deputy Director-General, Australian Signals Directorate, Committee Hansard, 


67 


12 July 2023, p. 14 


Mr Peter Anstee, Acting First Assistant Secretary, Department of Home Affairs, Committee Hansard, 


12 July 2023, p. 15. 


29 


writers note that Meta may incorporate these features in their future.‘ However, 
even in its current state, Threads is not currently available in the 
European Union because it does not comply with safety regulations.” 


2.87 Threads has been noted to collect more user data than Twitter: 


Threads is collecting almost everything it can, including data on your health, 
purchases, financial info, location, contact info, search history, and browsing 
history.” 


eSafety concerns with a decentralised internet 
2.88 The eSafety Commissioner published a position statement on a decentralised 
internet with the following summary: 
Under a decentralised internet, often referred to as 'DWeb' or 'Web 3.0', users 
are said to have more power because they can access online services and 
platforms without relying on a concentration of large technology companies 


that own or operate mainstream, centralised servers (the computer 
hardware and software that stores data). 


While decentralisation can allow users to protect their information and 
control their online experiences, it can also make it more difficult to hold 
users (or the entities behind them) responsible for illegal and harmful 
content and conduct 


2.89 The eSafety Commissioner noted some positives of decentralisation: 


e Decentralisation could improve the security, privacy and autonomy of 
online users by giving them greater control over their personal information 
and online experiences. 

e Decentralisation could also enhance freedom of expression and protect 
diversity of thoughts and opinions and reduce the risk of monitoring, 
tracking and targeting of at-risk or marginalised individuals or groups, 
including whistle-blowers and advocates for social change. 


2.90 Risks identified by the eSafety Commissioner included: 


e The absence of centralised servers and lack of central authority, along with 
the storage and distribution of data across many computers, makes it 
difficult to moderate or regulate decentralised services and platforms or 
enforce the removal of illegal and harmful content. A decentralised internet 


68 Jojo Percs, ‘How decentralized is Threads? Not at all for now', Medium, 8 July 2023, 
https://medium.com/@jojo_percs/how-decentralized-is-threads-not-at-all-for-now-87279710539e 
(accessed 10 July 2023). 


6 Dan Milmo, "Threads app: Instagram owner's Twitter rival logs 5 million users in first hours’, 
The Guardian, 6 July 2023. 


70 Stan Schroeder, 'Threads, Meta's Twitter rival, is tracking you in all sorts of ways', Mashable, 


6 July 2023, https://mashable.com/article/threads-tracking-data (accessed 10 July 2023). 


30 


may become a haven for criminal activities and for users who have been 
removed from mainstream services and platforms. 

It would be up to communities on each platform to decide and apply 
standards, with a risk that unchecked online environments can allow a 
range of harms from abuses to grow, without providing any way for users 
to get help or for consequences to be imposed on those responsible. 

The inability to enforce standards for conduct and content within a 
decentralised internet may actually harm freedom of expression instead of 
improving it. 

Using decentralised services may give users more control over their 
information and online experiences, but it also increases their own 
responsibility for understanding and operating in unregulated 
environments and keeping their personal information secure. 


2.91 The eSafety Commissioner recommended that adopting a Safety by Design 


71 


approach when developing decentralised platforms can mitigate these risks, by 
including protections such as: 


* community moderation; 
e opt-in governance; 
e identity verification; and 


content moderation.” 


eSafety, Decentralisation —position statement, Wwww.esafety.gov.au/industry/tech-trends-and- 
challenges/decentralisation (accessed 10 July 2023). 


3.1 


3.2 


Chapter 3 
International issues 


As outlined in Chapter 1, foreign interference, through social media and other 
methods, is an issue affecting liberal democracies around the world. 
This chapter outlines some of the main countermeasures being undertaken in 
nations and regions which are key security partners of Australia: the 
European Union (EU) and the nations which—with Australia—make up the 
'Five Eyes' intelligence alliance: the United States, Canada, United Kingdom and 
New Zealand. 


Finally, the chapter outlines security risks in the Pacific region and looks at a 
few examples of international digital literacy campaigns. 


Europe 


3.3 


In recent years, the EU has been contending more and more with the issue of 
social media and cyber-enabled foreign interference, alongside the related 
threats of cyber-security, data security and privacy. As early as 2015, the 
European Council was publicly stressing 'the need to challenge Russia's ongoing 
disinformation campaigns’ and called for ‘an action plan on strategic 
communication’.! 


European Union Agency for Cyber Security 


3.4 


1 


The European Union Agency for Cyber Security (ENISA), published a report in 
December 2022, Foreign Information and Interference (FIMI) and Cybersecurity — 
Threat Landscape. The report outlines how the concept of FIMI has been proposed 
as a response to the call of the European Democracy Action Plan for 'refined 
common definitions and methodologies in order to address different categories 
of disinformation and influence activities.' The report states: 


Although disinformation is a prominent part of FIMI, FIMI puts emphasis 
on manipulative behaviour, as opposed to the truthfulness of the content 
being delivered ... one of the main motivations behind this report is to 
identify ways to bring the cybersecurity and counter-FIMI communities 
closer together. The ambition is to provide an input to the on-going and ever 
pressing discussion on the nature and dynamics of information 
manipulation and interference, including disinformation, and on how to 
collectively respond to this phenomenon. The report proposes and tests an 
analytical approach describing FIMI and manipulation of information, as 


European Council conclusions, 20 March 2015, EUCO 11/15, p. 5. 


31 


32 


3.5 


well as the underlying cybersecurity elements, by combing practices from 
both domains.? 


This approach is now replicated across many EU agencies, which tend to define 
interference activities based on outcomes sought rather than tactics being used: 
focus is directed to the overall goals of the interference—manipulation of the 
information environment—as opposed to whether the information itself is 
misinformation or disinformation. 


European Parliament 


Special committee on Foreign Interference 


3.6 


3.7 


3.8 


3.9 


3.10 


The first Special Committee on Foreign Interference in all Democratic Processes 
in the European Union, including Disinformation (INGE 1), was established in 
2020. INGE 1 was tasked to report on factual findings and recommendations 
concerning the measures and initiatives to be taken in countering foreign 
interference and disinformation. 


After eighteen months of work—including 50 hearings with over 130 invitees — 
the report of the committee identified and mapped the threat of foreign 
interference in all its forms and provided a diagnosis of the EU's vulnerabilities 
and recommendations for strengthening the EU's resilience.’ 


INGE 2 was established in 2022 with a revised mandate to follow up on the 
implementation of the INGE 1 report, and to engage in a dialogue with policy 
makers at the national, the European and the international levels to contribute 
to the overall institutional resilience against foreign interference, hybrid threats 
and disinformation in the run-up to European elections in 2024. 


Since May 2022, INGE 2 has spoken with as many as two dozen experts and 
policy makers. In order to best focus on institutional and legislative resilience 
building in the run-up to European elections in 2024, INGE 2 established a close 
cooperation with North Atlantic Treaty Organization StratCom in Riga (Latvia), 
the Hybrid Centre of Excellence in Helsinki (Finland), with the 
Australian Government, and authorities and respective bodies at the 
United Nations in New York. 


The INGE 2 report included recommendations and updates on the EU's 
coordinated strategy against foreign interference; on EU resilience building; on 
interference using online platforms; on the critical infrastructure and strategic 
sectors; on interference during electoral processes; on covert funding of political 
activities by foreign actors and donors; on cybersecurity and resilience of 


2 European Union Agency for Cyber Security, Foreign Information and Interference (FIMI) and 
Cybersecurity — Threat Landscape, December 2022, p. 4. 


3 Special Committee on foreign interference in all democratic processes in the European Union, 
including disinformation (INGE 1), REPORT on foreign interference in all democratic processes in the 
European Union, including disinformation, (2020/2268(INI). 


33 


democratic processes; on the impact of interference on the rights of minorities 
and other vulnerable groups; on deterrence, attribution and collective 
countermeasures, including sanctions; and on neighbourhood policy, global 
cooperation, and multilateralism.‘ 


EU Digital Services Act 

3.11 Passed in 2022 and in force from 1 January 2024, the Digital Services Act updates 
and harmonises the legal framework for regulating illegal content — including 
disinformation — on digital intermediaries across the EU and co-regulates 
platforms along with the 2022 Code of Practice on Disinformation (EU code). The 
Digital Services Act requires all online platforms with more than 45 million 
European users (known as Very Large Online Platforms, or VLOPs) to have 
measures in place to mitigate risks from the spread of illegal content', with 
‘different purposes and enforcement remedies [through the EU code], 
depending on whether an organisation is a VLOP or another category of 
organisation’. 


European Commission—tackling online disinformation 

3.12 As part of its European Democracy Action Plan and complementary to the 
General Data Protection Regulation, the European Commission (EC) issued a 
Communication on Tackling online disinformation: a European approach in 2018.6 
As part of this approach, the EC committed to a range of initiatives to address 
disinformation across the EU, including through making online platforms more 
accountable, such as: 


* recognition of the voluntary EU code, strengthened further in 2022, 
including misinformation into the code scope, and measures demonetising 
pedlars of disinformation, transparency of political advertising, reducing 
manipulative behaviour, better informing users, expanding fact-checking 
coverage, and improving transparency and reporting; 

e developing the Action Plan against Disinformation’; and 

e establishing the European Digital Media Observatory — independent fact 
checkers and independent researchers. 


Special Committee on foreign interference in all democratic processes in the European Union, 
including disinformation (INGE 2), REPORT on foreign interference in all democratic processes in the 
European Union, including disinformation, 2022/2075(INI). 


5 Australian Communications and Media Authority, Submission 6, p. 3; Department of Infrastructure, 
Transport, Regional Development, Communications and the Arts, Submission 7, p. 3; 
European Commission, The Digital Services Act package, https://digital-strategy.ec.europa.eu/ 


en/policies/digital-services-act-package (accessed 2 March 2023). 


6 European Commission, Communication from the Commission to the European Parliament, the Council, 
the European Economic and Social Committee and the Committee of the Regions: Tackling online 


disinformation: a European approach, 24 April 2018, pp. 1-16. 


European Commission, Action Plan against Disinformation, 5 December 2018. 


34 


3.13 In February 2023 a Transparency Centre was announced including baseline 


reports on actions taken by major online platforms in response to 
disinformation.: In relation to the baseline reports, the EC noted that: 


Most major online platforms (Google, Meta, TikTok and Microsoft) 
demonstrated strong commitment to the reporting, providing an 
unprecedented level of detail about the implementation of their 
commitments under the Code, and—for the first time—data at 
Member State level. Twitter, however, provides little specific information 
and no targeted data in relation to its commitments. ° 


3.14 Reports from online platforms referenced foreign interference matters, 


including in relation to elections, the 'war of aggression by Russia on Ukraine’, 
and Commitment 16 relating to cross-platform influence operations and foreign 
interference. 


European External Action Service 
3.15 The European External Action Service (EEAS) is the EU diplomatic service. In 


2015, the EEAS established its own disinformation unit— East StratCom Task 
Force—following the calls outlined above for greater action against 
disinformation. Since then, a number of reports and initiatives have been 
undertaken, as outlined below. 


EUvsDISINFO 
3.16 In 2015, East StratCom Task Force launched a project, EUvsDiSInfo, 'to increase 


public awareness and understanding of the Kremlin's disinformation 
operations, and to help citizens in Europe and beyond develop resistance to 
digital information and media manipulation’. EUvsDiSInfo states that it uses 
‘data analysis and media monitoring services in 15 languages, EUvsDisinfo 
identifies, compiles, and exposes disinformation cases originating in 
pro-Kremlin media that are spread across the EU and Eastern Partnership 
countries'."! 


Australian Communications and Media Authority, Submission 6, p. 3; European Commission, 


Tackling online disinformation, https://digital-strategy.ec.europa.eu/en/policies/online- 
disinformation (accessed 1 March 2023). 


European Commission, Signatories of the Code of Practice on Disinformation deliver their first baseline 
reports in the Transparency Centre, https://digital-strategy.ec.europa.eu/en/news/signatories-code- 
practice-disinformation-deliver-their-first-baseline-reports-transparency-centre 

(accessed 1 March 2023). 


See, for example: TikTok, Code of Practice on Disinformation — Report of TikTok for the period 16 June- 
16 December 2022, pp. 51, 77 and 143. 


EUvsDisInfo, About, https://euvsdisinfo.eu/about/ (accessed 7 July 2023). 


35 


EEAS Report on Foreign Information Manipulation and Interference Threats 
3.17 In June 2022, a workshop of high-level experts from civil society, industry, and 


3.18 


3.19 


3.20 


3.21 


government was convened to take stock of best practices in the FIMI analyst 
community by the (Carnegie Endowment for International Peace. 
That workshop identified a key barrier to addressing FIMI was the lack of 
agreed upon definitions and analytical standards for analysing and reporting 
on FIMI.” 


Following on from that workshop, the EEAS released the 1st EEAS Report on 
Foreign Information Manipulation and Interference Threats (EEAS report) in 
February 2023 to: 
... provide the FIMI defender community with a proof-of-concept for a 
common framework that enables mutual sharing of complex insights in a 


timely fashion and at scale. This is done to create a common understanding 
and formulate a collective, systematic response to FIMI.!3 


The EEAS report had three main components: 


e a pilot FIMI threat analysis on priority actors and issues in 2022; 

e abehaviour-first approach to FIMI detection and analysis, as well as the 
linked DISARM 'Kill Chain' perspective on FIMI; and 

e an analytical framework for FIMI threat analysis." 


The EEAS report proposed using the Disinformation Analysis and Risk 
Management (DISARM) open-source framework, which is: 
... designed for describing and understanding the behavioural parts of 
FIMI/disinformation. It sets out best practices for fighting disinformation 
through sharing data & analysis, and can inform effective action. The 
Framework has been developed, drawing on global cybersecurity best 
practices. 


The DISARM framework builds on the ABCDE framework of differentiating 
FIMI incidents 'in terms of actors, behaviours, content, degree, and effect’ which 
is seen as a ‘helpful mnemonic for both investigators and readers to check 
whether an analysis covers every important aspect of a FIMI incident’. 
The DISARM framework goes further, to articulate an analysis cycle that is 
self-reinforcing, in that 'the more often the analytical workflow is applied, the 
better informed each research iteration will become’: 


Carnegie Endowment for International Peace, Partnership for Countering Influence Operations, 


https://carnegieendowment.org/specialprojects/counteringinfluenceoperations/ 
(accessed 15 May 2023). 


13 European Union External Action Service (EEAS), 1st EEAS Report on Foreign Information 
Manipulation and Interference Threats, p. 5. 


14 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 7. 


15 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 4. 


36 


Figure 3.1 Self-reinforcing workflow for strategically analysing incidents of 
Foreign Information Manipulation and Interference 


Situational 
Awareness Strategic 
Monitoring 


Knowledge 

Pooling 

& Sharing Prioritisation 
& Triage 


Incident Analysis & 
Evidence Collection 


Source: European Union External Action Service, 1st EEAS Report on Foreign Information Manipulation and 
Interference Threats, p. 27. 


3.22 The FEAS report noted the importance of taking a systematic approach to 


developing countermeasures, as well as then measuring the success of different 
strategies. 16 


3.23 The EEAS report also emphasised the importance of ensuring countermeasures 


are appropriate to the seriousness of the particular threat, noting that the point 
of countering FIMI is to protect the integrity of the democratic process and 
universal values. For example, where anonymity is a key tactic of a FIMI actor, 
government responses must 'weigh whether challenging that central feature of 
the internet is proportionate to tackling the risk'.”” 


3.24 The EEAS report identified a range of countermeasures that can be taken to 


16 


17 


address FIMI: 


e Statement of Refutal: An involved entity issued a statement refuting the 
claims of the incident. 
e Debunking: The claims of the incident were debunked/fact-checked. 


EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 26. 


EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 26. 


37 


e Content Deleted: Content of any type was taken down in response to the 
incident. 

e Content Confined: Content of any type was limited in response to the 
incident. 

e Channel Limited or Suspended: The channel of any of the observables 
was limited or suspended in response to the incident. 

e Other: Any other counter measure that is not captured by the above 
taxonomy.'® 


3.25 The EEAS report highlighted an additional tactic to the above, which is to use a 
"Kill Chain’ approach as modified by the DISARM Foundation for use against 
FIMI. This approach recognises that a single FIMI incident has many necessary 
steps—planning, creating and disseminating content—and to deny a threat 
actor any one of those steps effectively kills off the attack: 

This approach builds upon positive experience in cybersecurity, where the 
forensic analysis of threat actor behaviour throughout the entire timeline of 
their attempted attack has helped to better understand systemic 
vulnerabilities, and how to spot and close their exploitation to prevent the 
infiltration of and damage to computer systems.” 

3.26 Most importantly, the Kill Chain approach acknowledges that each step of the 
FIMI chain requires not only different approaches to detection and analysis, but 
also requires different countering strategies and techniques.” 


3.27 Figure 3.2 below shows the four identified stages of a FIMI incident, each of 
which then allows for a different strategy and techniques to disable that stage 
and ‘kill’ the entire incident: 


18 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 24. 


19 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 26. 


2 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 26. 


38 


Figure 3.2 DISARM Foundation—Kill Chain 


DISARM KILL CHAIN 


PREPARE EXECUTE ASSESS 


Develop Leverage Conduct Measure 
Narratives Existing Pump Priming Performance 
Narratives TA T 


Trial Content 


Pian Strategy 


Create hashtags 
and search 
artifacts 


Deliver 
Content 


Develop 
Content 


Target Audiences Deliver Ads 


Plan Objectives 

Create 

inauthentic Flooding the 
Social Media Information Space 
Pages and T004 

Groups 


Facilitate State 
Propaganda 


Establish Drive Online Censor Social 
Target Audience Legitimacy Harms Media as a 
Analysis Creste Political Force 
Fake Experts -0 7 


Segment Audiences 
Drive Offline Conduct 
Activity Fundraising 
Al f 


Select Channels Online Polls Persist in the Play the A 
and Affordances Information Long Game Effectiveness 
Environment 


Source: EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 29. 


Visualisation of the DISARM framework’s threat actor Kill Chain (Red Team). Red dots represent the overarching 
tactics (TA) at a given stage, blue dots show examples of techniques (T) used under a given tactic. 

3.28 The EEAS report noted that in order for a Kill Chain approach to be helpful, it 
must be supported by objective analysis of the behaviour and tactics, techniques 
and procedures (TTPs) threat actors use, as well as systematic development and 
measurement of disruptive responses.” 


3.29 The EU Agency for Cyber Security noted that having a community of multiple 
FIMI countermeasure actors from different sectors enables any response to be 
tailored by choosing the best political actor to respond to a specific FIMI event.” 


3.30 The EEAS report also found that large-scale collaboration required a ‘common 
data format for sharing threat information’ that was ‘able to represent all 
fundamental building blocks (or objects) of a threat and express how they are 
related to one another’. The report further noted of FIMI data standards: 

It would also have to be flexible enough to remain useful while the threat 
keeps evolving, but stable enough to allow for the adaptation of processes 
and the building of tools on top of it. Lastly, it should follow the same 


principles of openness, community involvement and universality as 
commonly shared taxonomies to find wide adoption.” 


3.31 The report recommended the adoption of the existing Structured Threat 
Information Expression (STIX™) format used for cyber threat information, and 


21 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 26. 
2 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 26. 


3 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 30. 


39 


3.32 


suggested it be updated to STIX2.1 with custom extensions needed for 
idiosyncratic FIMI threat indicators.” 


Notably, on 31 May 2023, the EU-United States (US) Trade and Technology 
Council announced it has adopted the DISARM and STIX2 frameworks as 
'a common standard for exchanging structured threat information on FIMT': 


This standard that the European Union and the United States are now using 
to analyse FIMI and share information is comprised of the DISARM 
framework, the STIX2 standard and the OpenCTI [open cyber threat 
intelligence] platform. This approach will significantly strengthen our 
collective efforts to identify, analyse and counter FIMI by enhancing our 
common situational awareness of FIMI threats. At the same time, this 
standard and its elements are made up of open-source solutions, which is 
key to ensure an approach that can be used by stakeholders around the 
globe.» 


Information Sharing and Analysis Center 


3.33 


Announced on 7 February 2023, the EU has launched a new platform to counter 
disinformation campaigns by Russia and China. The Information Sharing and 
Analysis Center within the EEAS will track information manipulation by foreign 
actors and coordinate with the 27 EU countries and the wider community of 
non-government organisations (NGOs). It will be a decentralised platform to 
exchange information in real-time with NGOs, countries and cybersecurity 
agencies, enabling better understanding of emerging disinformation threats and 
narratives and quicker action to tackle such problems.” 


TikTok in the EU 


TikTok bans 
3.34 The European Parliament, EC, and the EU Council, the three top EU bodies, 


have all banned TikTok on staff devices, citing cybersecurity concerns. 
Individual EU nations that have imposed similar bans as of 4 April 2023, include 
France, the Netherlands, Norway and Denmark.” 


Project Clover 


3.35 


As part of its efforts to allay fears about misuse of user data and privacy 
concerns, TikTok has begun what it refers to as Project Clover, which the 


24 EEAS, 1st EEAS Report on Foreign Information Manipulation and Interference Threats, p. 30. 


25 EFAS, Trade and Technology Council, Trade and Technology Council Fourth Ministerial — Annex on 
Eoreign information manipulation and interference in third countries, 31 May 2023, p. 1. 


26 Clothilde Gioujard, 'EU to launch platform to fight Russian, Chinese disinformation', Politico, 
7 February 2023. 


27 Euronews, 'Which countries have banned TikTok and why?', 4 April 2023. 


40 


3.36 


3.37 


company said in an 8 March 2023 statement builds on its data approach in the 
US, writing: 
... we are further enhancing these controls by introducing security gateways 
that will determine employee access to European TikTok user data and data 
transfers outside of Europe. This will add another level of control over data 
access. Any data access will not only comply with the relevant data 
protection laws but also have to first go through these security gateways and 
additional checks.”* 


TikTok also reported that it was working on additional privacy enhancing 
technologies that included '‘pseudonymisation of personal data so that an 
individual cannot be identified without additional information and aggregation 
of individual data points into large data sets to protect the privacy of 
individuals’. 

TikTok also announced a number of European data centre sites in Europe as 
part of what it said was its 'commitment to store European TikTok user data 
locally’, outlining that it would begin storing European user data locally in 2023, 
with migration continuing into 2024, at an overall cost of €1.2 billion.” 


Agreement between EU and United States on transatlantic cooperation 


3.38 


In May 2023, the EU and the US announced a number of actions to increase 
transatlantic cooperation to proactively address FIMI and disinformation: 


e Common methodology for identifying, analysing and countering FIMI 
The EU and the US have adopted a common standard for exchanging 
structured threat information on FIMI, through a more interoperable and 
machine-readable approach. When fully operational, information will be 
shared more efficiently, effectively and with a greater level of detail when it 
comes to understanding the manipulative tactics, techniques and 
procedures. This standard that the EU and the US are now using to analyse 
FIMI and share information is comprised of the DISARM framework, the 
STIX2 standard and the OpenCTI platform. 

e Enhancing the preparedness against FIMI in third countries together with Civil 
Society Organisations (CSOs) and platforms 
The EU and the US organised several workshops to bring together civil 
society organisations, academic institutions, and media outlets from Africa 
and Latin-America, as well as platforms active in these regions, to explore 
how a multi-stakeholder community can step up its actions in coordinating 
the response to FIMI. 
The EU and the US intend to further enhance support for capacity building 
in third countries, including by exploring additional actions to support and 


28 TikTok, Setting a new standard in European data security with Project Clover, 8 March 2023, 
https://newsroom.tiktok.com/en-ie/project-clover-ireland (accessed 16 July 2023). 


2 TikTok, Setting a new standard in European data security with Project Clover. 


41 


reinforce civil society and fact-checking organisations that facilitate the fight 
against FIMI on online platforms through our respective development 
funding mechanisms. 

e Call for action to platforms 
The EU and the US also called upon online platforms to ensure the integrity 
of their services and to effectively respond to disinformation and FIMI, 
building on the example of the EU's updated Code of Practice on 
Disinformation. 


United States 


Foreign Malign Influence Centre 
3.39 The Foreign Malign Influence Centre was established in September 2022. It is 


housed under the Director of National Intelligence and 'serves as the primary 
U.S. Government organization for analysing and integrating all intelligence and 
other reporting possessed or acquired pertaining to foreign malign influence, 
including election security'.*! 


Department of State— Global Engagement Centre 
3.40 The mission of the Global Engagement Centre of the Department of State is to 


3.41 


‘direct, lead, synchronize, integrate, and coordinate U.S. Federal Government 
efforts to recognize, understand, expose, and counter foreign state and non-state 
propaganda and disinformation efforts aimed at undermining or influencing 
the policies, security, or stability of the United States, its allies, and partner 
nations’. 


It does this through five areas of work: 


(a) Analytics and Research: collects data to produce analysis on foreign 
malign information influence narratives, tactics, and techniques, which is 
then shared with domestic and international partners. 

(b) International Partnerships: with other national governments for the 
purpose of coordinating counter-disinformation analyses and actions. 

(c) Programs and Campaigns: has issue specific teams to build societal and 
institutional resilience to foreign propaganda and disinformation efforts. 

(d) Exposure: has a coordination role in the exposure of foreign information 
influence operations. 


30 US EU Joint Statement of the Trade and Technology Council, Annex 3, 29 May 2023. 


31 Director of National Intelligence (US), The National Counterterrorism Center, Foreign Malign 
Influence Center Fact Sheet, Wwww.dni.gov/files/FMIC/documents/FMIC Fact Sheet.pdf 
(accessed 16 July 2023). 


42 


(e) Technology Assessment and Engagement: assesses counter- 
disinformation technologies against specific challenges, and identifies 
technological solutions through technology challenge programs.” 


TikTok & WeChat IEEPA Orders 
3.42 In August 2020, President Trump attempted to use powers under the 


International Emergency Economic Powers Act to ban TikTok and WeChat in the 
US, or to force ByteDance's divestment of TikTok to a non-Chinese company. 
A court case struck down the Executive Orders, which were subsequently 
withdrawn by President Biden.* 


RESTRICT ACT 
3.43 In response to the executive orders being struck out by legal challenges, on 


7 March 2023 a bipartisan group of 13 US Senators introduced a bill that would 
create the Restricting the Emergence of Security Threats that Risk Information 
and Communications Technology (RESTRICT) Act, which has been referred to 
a US Senate Committee for inquiry. The RESTRICT Bill creates an entirely new 
legislative framework that would allow the Secretary of Commerce to review 
and regulate foreign-linked tech firms for national security risks and then 
develop mitigating options.™ 


TikTok ban 
3.44 In late December 2022, the US government approved a ban on the use of TikTok 


on government owned devices. Reporting from February 2023 indicates TikTok 
has been banned from state government owned devices in half of the states, and 
a number of universities in the US are also reported to have banned the use of 
TikTok on their networks.* 


Project Texas 
3.45 Project Texas is similar to Project Clover, in that the US $1.5 billion project with 


32 


33 


34 


35 


technology company Oracle is designed to ensure that TikTok US user data 
remains stored in the US. However, whistleblowers have raised concerns that 


US Department of State, About Us — Global Engagement Center, www.state.gov/about-us-global- 
engagement-center-2/ (accessed 16 July 2023). 


Peter Jeydel and Brian Egan, 'An "IEEPA-Free Zone" for TikTok and other Chinese Mobile 
Applications?', American Society of International Law, 8 February 20221, Vol. 25 Issue 2. 


See: Cyber Risk GmbH, The Restrict Act, https://www.restrict-act.com/ (accessed 26 July 2023). 


Johana Bhuiyan, 'Why did the US just ban TikTok from _government-issued _cellphones?’, The 
Guardian, 31 December 2022; Alex Hern, 'Canada bans TikTok on government devices over security 
risks’, The Guardian, 1 March 2023. 


43 


this project will not genuinely protect data from being accessed by the 
Chinese Communist Party (CCP).% 


United Kingdom 


Defending Democracy Taskforce 
3.46 In November 2022, the United Kingdom (UK) established the 
Defending Democracy Taskforce, with its primary focus being 'to protect the 
democratic integrity of the UK from threats of foreign interference’. 
Those threats were listed as: 
foreign interference in our elections and electoral processes; 
disinformation; physical and cyber threats to our democratic institutions 


and those who represent them; foreign interference in public office, political 
parties and universities; and transnational repression in the UK.*” 


3.47 The taskforce reports into the UK's National Security Council. 


Counter Disinformation Unit 

3.48 The UK has a dedicated Counter Disinformation Unit that operates across 
government. Established in early 2020, its primary role at that time was to 
counter false COVID-19 narratives. However, it is now focused more widely on 
content targeted at UK audiences which poses a risk to public health, public 
safety, or national security, such as false COVID-19 'cures' or disinformation 
related to the Russian invasion of Ukraine.*” 


UK's TikTok ban 
3.49 On 16 March 2023, TikTok was banned from being installed on government 
devices, after Cabinet Office Ministers ordered a security review. The statement 
announcing the ban highlighted that: 
TikTok requires users to give permission for the app to access data stored 
on the device, which is then collected and stored by the company. Allowing 


such permissions gives the company access to a range of data on the device, 
including contacts, user content, and geolocation data. 


36 Dan Milmo, 'Six urgent questions TikTok's CEO needs to answer for US lawmakers’, The Guardian, 
22 March 2023. 


37 UK Home Office, 'Ministerial Taskforce meets to tackle state threats to UK democracy', Media release, 
28 November 2022. 


38 UK Government, ‘Ministerial Taskforce meets to tackle state threats to UK democracy', Media release, 
28 November 2023. 


3° Cabinet Office (UK), Fact Sheet on the CDU and RRU [Rapid Response Unit], 9 June 2023, 
www.gov.uk/government/news/fact-sheet-on-the-cdu-and-rru (accessed 15 July 2023). 


44 


The government, along with our international partners, is concerned about 
the way in which this data may be used.*° 


National Security Act 2023 
3.50 The National Security Act 2023 came into effect on 11 July 2023 and ‘introduces 


3.51 


new measures to modernise counter-espionage laws and address the evolving 
state threat to national security’. The Home Office (UK) stated: 
The act introduces an offence of foreign interference, meaning it will now be 
illegal in the to engage in conduct that interferes with fundamental rights, 


such as voting and freedom of speech, that are essential to the UK's 
democracy. 


The act also introduces a Foreign Influence Registration Scheme, similar to that 
operating in Australia.” 


Online Safety Bill 
3.52 The Online Safety Bill, which as of July 2023 is before the House of Lords, 


integrates closely with the National Security Act 2023 described above. It does 
this by designating foreign interference offences under the National Security Act 
as ‘priority offences’ under the Online Safety Bill. The UK Government 
described the effect of this amendment to the Online Safety Bill on 5 July 2022: 


It means social media platforms, search engines and other apps and websites 
allowing people to post their own content will have a legal duty to take 
proactive, preventative action to identify and minimise people's exposure to 
state-sponsored or state-linked disinformation aimed at interfering with the 
UK. 


Canada 


3.53 


Electoral foreign interference, hybrid threats and cyber-enabled social media 
operations, including the use of cyber-attacks, have also been part of Chinese 
foreign interference techniques recently identified in Canada. This follows the 
leak in early 2023 of government intelligence documents by a whistleblower to 
the Globe and Mail newspaper, which reported: 
Highly classified CSIS [Canadian Security Intelligence Service]}documents 
seen by The Globe paint a picture of a broad Chinese strategy to interfere in 
Canada's democracy and gain influence over politicians, corporate 
executives, academics and vulnerable Chinese Canadians. The documents 
reveal that Beijing's ruling Chinese Communist Party uses three 


4 Cabinet Office (UK), 'TikTok banned on UK government devices as part of wider app review’, 
Media release, 16 March 2023. 


4 Home Office (UK), National Security Act 2023, www.gov.uk/government/collections/the-national- 
security-bill (accessed 15 July 2023). 


42 Department for Digital, Culture, Media and Sport UK, ‘Internet safety laws strengthened to fight 
Russian and hostile state disinformation’, Press release, 5 July 2022; UK Parliament, Online Safety Bill, 


https://bills.parliament.uk/bills/3137 (accessed 26 July 2023). 


45 


colour-coded 'political-interference tactics' to gain influence over Canadians 
here and those travelling to China.* 


3.54 The CSIS Public Report 2021 also identifies the role cyber-attacks are playing in 


foreign interference campaigns, including on social media, providing an 
infographic and outlining that: 


State-sponsored disinformation campaigns represent one of many vectors of 
foreign interference and hostile states have been involved in actively 
spreading disinformation in an effort to discredit our government 
institutions, negatively impact social cohesion and gain influence for their 
own strategic objectives. 


Foreign Influence Registry 
3.55 Canada has recently begun public consultation on the creation of a foreign 


influence registry, and in this process Australia's Foreign Influence 
Transparency Scheme has been included in the benchmarking that accompanied 
the consultation document. Canada also appears to be following a similar 
approach to Australia and considering appointing a National Counter Foreign 
Interference Coordinator position within Public Safety Canada. 


TikTok ban 
3.56 Following a review of TikTok from the Chief Information Officer of Canada, in 


February 2023 the Canadian Government banned TikTok on government-issued 
devices. As has been the case with other jurisdictions, the public messaging in 
relation to the bans has been heavily framed in relation to the cyber security and 
privacy threat the app poses instead of foreign interference considerations.” 


New Zealand 


Concern for 2023 elections 
3.57 On 27 March 2023, media reported that 'New Zealand intelligence agencies are 


43 


44 


45 


46 


47 


growing more concerned about both foreign interference and malicious cyber 
activity ahead of elections in October'. Phil McKee, Acting Director-General of 
Security, said the threat of foreign interference and espionage is a growing cause 


Steven Chase, 'A timeline of China's alleged interference in recent Canadian elections', The Globe 
and Mail, 9 March 2023 (accessed 26 July 2023). 


Canadian Security Intelligence Service, CSIS Public Report 2021, March 2022, p. 18. 


Public Safety Canada, Enhancing Foreign Influence Transparency: Exploring Measures to Strengthen 
Canada’s Approach, www.publicsafety.gc.ca/cnt/rsrcs/pblctns/2023-nhneng-frgn-nfluence/index- 


en.aspx (accessed 7 July 2023) 


‘Ottawa considering appointing a national coordinator to counter foreign interference, minister 
says', CBC News, (accessed 7 July 2023). 


Alex Hern, ‘Canada bans TikTok on government devices over security risks’, The Guardian, 
1 March 2023. 


46 


for concern, adding information was being collected on those who speak out 
against foreign governments and their families being threatened in their home 
countries.* 


3.58 On 10 March 2023 New Zealand media reported on comments made by a 


member of the government's Independent Electoral Review Panel, in which it 
was indicated that the potential for artificial intelligence to be used to spread 
misinformation and disinformation in the lead-up to the October 2023 election 
was a topic under consideration.” 


3.59 Earlier in July 2021, statements made by the New Zealand Director-General of 


Security to the Justice Committee Inquiry into the 2020 General Election and 
Referendums, outlined that 'state actors pursuing their strategic goals through 
disinformation is an area of growing international concern’ and went on to note 
that: 


We assess that New Zealand has not been the direct target of widespread 
state-backed disinformation campaigns. But given the nature of global 
online content, members of the New Zealand public are highly likely to 
encounter disinformation. This means that disinformation campaigns 
occurring overseas may affect levels of trust in the media and government 
here,?? 


TikTok ban on parliamentary devices 


3.60 On 17 March 2023, the parliamentary service chief executive 


Rafael Gonzalez-Montero wrote to New Zealand MPs that the TikTok 
application would be banned from parliamentary work devices after 
determining that the ‘risks are not acceptable in the current New Zealand 
Parliament environment’. This decision was based on the parliamentary 
service’s analysis and discussions with colleagues across government and 
internationally.” 


Pacific region 
3.61 A recent report by the Australian Strategic Policy Institute noted that the 


48 


49 


50 


51 


Indo-Pacific region ‘contains an arc of emergent democracies vulnerable to 
Lucy Craymer, 'New Zealand security chiefs increasingly concerned about foreign interference’, 
Reuters, 27 March 2023. 


Geraden Cann, ‘Artificial intelligence ‘likely to be used to spread disinformation’ during next 
election’, Stuff, 10 March 2023. 


Director-General of Security, New Zealand Security Intelligence Service and Acting Director- 
General of the Government Communications Security Bureau, Director-General remarks: Justice 
Committee Inquiry into the 2020 General Election and Referendums, www.nzsis.govt.nz/news/director- 
general-remarks-justice-committee-inquiry-into-the-2020-general-election-and-referendums/ 
(accessed 7 July 2023). 


Michael Neilson, ‘TikTok app banned on phones of New Zealand MPs by Parliamentary Service 
amid security concerns’, NZ Herald, 17 March 2023. 


47 


coercive statecraft and foreign interference and further noted that some ‘have 
limited civil society organisations or independent media’. The report 
recommended: 


The US and Australian governments should invest more in fostering 
democratic resilience in a region that has high levels of digital penetration. 
Many countries in the Indo-Pacific are coming from a low base in terms of 
their capacity to engage with hybrid threats in the security landscape ... 
There's much that the US and Australia can do to build capacity and 
resilience among partners in the region. A construct such as a regional 
hybrid threats centre could provide an effective vehicle to bring together 
this cross-section of stakeholders—from governments, industry and civil 
society—to engage with the diversity of the region and the diversity of 
threats.* 


3.62 Dr William Stoltz of the Australian National University, also noted that work 
needs to be done by Australia to support countermeasures against foreign 
interference in the Pacific region: 


... there is arguably a greater problem concerning foreign interference on 
social media in the countries that are closest to us and most key to our 
interests. This is particularly those countries in the South Pacific, where 
there isn't necessarily the fulsome law enforcement and digital 
infrastructure that we might have to provide online safety. I would say that 
amore urgent priority for Australia, alongside our own jurisdiction, is to be 
investing in the digital literacy and the infrastructure of developing 
countries in our region, which we know are the targets of quite 
comprehensive information operations by other states. Those countries, just 
through the underdeveloped nature of their institutions, are more 
vulnerable to these malicious information operations.” 


3.63 Meta advised the committee of work it is undertaking in the Pacific region, via 
its Pacific Islands advisory group: 

[W]e've been able to develop a locally relevant digital campaign which 
advises and educates people across a number of different channels. It's done 
in a range of local languages and in ways that, hopefully, are compelling to 
people, to give them some tips, and in ways to provoke them to think about 
what they're sharing and the content they're engaging with. We've also got 
teams that work across the region on broader digital literacy campaigns as 
well.4 


International digital literacy campaigns 
3.64 This section outlines key digital literary campaigns that have taken place 
abroad, many of which seek to mitigate the impact of foreign interference, 


52 Danielle Cave and Dr Jacob Wallis, Australian Strategic Policy Institute, 'Cyber-enabled foreign 
interference’, Strategic Insights, November 2022, pp. 21-22. 


3 Dr William Stoltz, Private capacity, Committee Hansard, 20 April 2023, p. 40. 


54 Ms Mia Garlick, Regional Director of Policy, Meta, Committee Hansard, 11 July 2023, p. 9. 


48 


misinformation and disinformation online. These campaigns could act as 
models for a prospective Australian public education campaign. 


United States 


3.65 


3.66 


The Federal Bureau of Investigation's Protected Voices Initiative provides 
information to the public on the nature of foreign cyberattacks aimed at 
influencing American political processes. The Department of Homeland 
Security's Cybersecurity and Infrastructure Security Agency (CISA) have also 
published a range of infographics and documents aimed at raising awareness 
and educating individuals on how to resist foreign interference through social 
media.® 


In anticipation of the 2020 Presidential election, CISA launched the 
'#Protect2020' campaign. The campaign involved support for election officials in 
identifying and planning for vulnerabilities within election infrastructure.” 


United Kingdom 
3.67 The UK Government has developed disinformation tools and campaigns 


including: 


° The 'Don't Feed the Beast’ campaign educates the public on the dangers of 
sharing inaccurate information online. 

e A ‘train the trainer’ plan which equips teachers, library workers and carers 
with skills needed to assess information viewed online. 

e A toolkit to help communicators manage the impact disinformation could 
have on their organisation.” 


European Union 


3.68 


The European Commission has organised a range of initiatives to increase levels 
of digital and media literacy, such as the 2019, European Media Literacy Week 
including 320 events across the continent and the Social Observatory for 
Disinformation and Social Media Analysis which 'provide strategies and actions 
to increase media literacy'.* 


5 Jelisa Castrodale, "The US Government is using pineapple pizza to explain Russian political 
interference’, Vice, 27 July 2019; Jacob Ward, 'U.S. cybersecurity agency uses pineapple pizza to 
demonstrate vulnerability to foreign influence’, NBC, 27 July 2019; Federal Bureau of Investigation, 


Protected Voices: Social Media Literacy, www.fbi.gov/video-repository/protected-voices-social- 
media-literacy-102319.mp4/view (accessed 3 March 2022). 


56 Law Council of Australia, Submission 18, p. 35. 


5 Government of the United Kingdom, SHAREChecklist, 2020, https://sharechecklist.gov.uk/ 
(accessed 3 March 2022); Australasian Cyber Law Institute, Submission 41, p. 20. 


58 Law Council of Australia, Submission 18, p. 48. 


49 


3.69 As outlined earlier in this chapter, the EUvsDisinfo campaign aims to increase 
public awareness of ‘disinformation operations and campaigns and increase 
resistance to digital information and media manipulation’. 


Canada 

3.70 The Canadian Government has developed the Digital Citizen Initiative to 
‘support democracy and social cohesion in Canada by building citizens' 
resilience against online disinformation and building partnerships to support a 
healthy information ecosystem’. 


Ukraine 

3.71 In 2015, the Ukrainian Government introduced the Learn to Discern program in 
schools to improve young people's media literacy particularly in the context of 
propaganda campaigns led by the Russian Government which sought to 
destabilise Ukrainian public institutions.“ 


3.72 The success of the program led to its adoption in other countries and some 
submitters recommending that Australia adopt a similar program here. 


5 Law Council of Australia, Submission 18, p. 46. 
60 Department of Home Affairs, Submission 16, p. 8. 
61 Australasian Cyber Law Institute, Submission 41, p. 23. 


62 See Law Society of New South Wales: Young Lawyers, Submission 11, p.10; and University of New 
South Wales Law Society, Submission 37, p. 28. 


4.1 


4.2 


Chapter 4 
Government: Current practice 


In order to identify gaps in countermeasures that governments can take towards 
foreign interference through social media, it is vital to accurately map the steps 
currently being taken. 


This chapter outlines current legislation and taskforce initiatives of the 
Australian Government to attempt to combat the impact of foreign interference 
and disinformation on social media. 


Current legislative settings 


4.3 


As noted in the interim report of the Select Committee on Foreign Interference 
through Social Media established during the 46th Parliament (2019 select 
committee), while several pieces of legislation apply to social media and the 
online environment—such as those that seek to protect user privacy and prevent 
criminal activity online—none specifically address the problem of foreign 
interference through social media. 


Criminal Code Act 1995 


4.4 


4.5 


4.6 


4.7 


4.8 


The Criminal Code Act 1995 (Criminal Code) contains provisions that criminalise 
foreign interference (section 92.3). 


These provisions were used to charge Mr Di-Sanh Duong ‘with the offence of 
preparing for a foreign interference offence, contrary to section 92.4 of the 
Criminal Code’. This matter is still before the courts." 


On 14 April 2023, the Australian Federal Police (AFP) charged 
Mr Alexander Csergo with the offence of reckless foreign interference, contrary 
to section 92.3 of the Criminal Code. This matter is still before the courts. 


These provisions were also used in the June 2020 investigation of 
Mr John Zhisen Zhang, a part-time staffer of New South Wales (NSW) 
Labor MP Mr Shaoquett Moselmane. The AFP alleged that Mr Zhang and 
unnamed others used a WeChat group to advance the interests and policy goals 
of China by providing support and encouragement to Mr Moselmane for the 
advocacy of 'Chinese state interests’ within the NSW Labor Party and to voters. 


It was later revealed that the AFP-Australian Security Intelligence Organisation 
(ASIO) Foreign Interference Taskforce had also taken action in relation to 


Attorney-General’s Department, Submission 25, p. 4. 


Australian Federal Police, ‘Australian man charged with foreign interference’, Media Release, 
14 April 2023; Echo Hui, ‘Bondi man Alexander Csergo was warned to leave China by American 
contact he suspected was a spy’, ABC News, 28 June 2023. 


51 


52 


six Chinese citizens suspected to be part of a group of foreign agents who 
encouraged and helped Mr Moselmane to champion Chinese Government 
interests, including two academics who had their visas cancelled and four 
Chinese journalists who departed Australia after raids on their media outlets.’ 


National Security Legislation Amendment (Espionage and Foreign Interference) 
Act 2018 


4.9 


The Australian Government updated the offences in the Criminal Code via the 
National Security Legislation Amendment (Espionage and Foreign Interference) Act 
2018 (Espionage Act) to introduce new offences relating to foreign interference 
with Australia's political, governmental or democratic processes. These new 
foreign interference offences could be applied to persons who 'weaponise' fake 
news in certain circumstances. 


4.10 The offences contained in the Espionage Act now extend to persons who, on 


behalf of a foreign government, engage in the deceptive or covert conduct 
intended to ‘influence a political or governmental process of the Commonwealth 
or a State or Territory or influence the exercise (whether or not in Australia) of 
an Australian democratic or political right or duty'.5 


4.11 At time of writing, two separate people have been charged under the 


Espionage Act, for actions not relating to social media. In the first case, 
Dr Sunny Duong is alleged to have sought to cultivate a relationship with 
former Coalition Minister Alan Tudge from March to June in 2020 and use that 
relationship to advance the interests of the Chinese Communist Party.° 


4.12 The second case is that of Australian businessman Alexander Csergo, who was 


charged with reckless foreign interference in April 2023. Mr Csergo lived in 
China for decades and is alleged to have been recruited by suspected agents for 
China's Ministry of State Security, 'Ken' and 'Evelyn', to obtain and provide 
information on intelligence priorities. It is alleged they first made contact with 
Mr Csergo via professional networking platform, LinkedIn.’ 


Sean Rubinsztein-Dunlop and Echo Hui, 'Australian police accessed Chinese diplomats' emails and 
messages as part of foreign political interference investigation’, ABC News, 15 September 2020. 


For a fulsome description of the changes that took place, see Juli Tomaras, Owen Griffiths, David 


Markham and Claire Petrie, National Security Legislation Amendment (Espionage and Foreign 
Interference) Bill 2017, Bills Digest No 134, 2017-18, Parliamentary Library, Canberra. 


National Security Legislation Amendment (Espionage and Foreign Interference) Act 2018, s 83.4. 


Hugo Timms, ‘Sunny Duong: Alleged Chinese spy who donated to Liberal politician Alan Tudge 
faces court’, News.com.au, 28 July 2022. 


Tory Shepherd, ‘Vague foreign influence laws in focus as Australian businessman accused of taking 
money from spies’, the Guardian, 23 April 2023; and Kirsty Needham and Lewis Jackson, ‘How 
Chinese spies allegedly tried to force Bondi man into sharing secrets about AUKUS in exchange for 
envelopes full of cash’, Daily Mail, 17 April 2023. 


53 


4.13 Both cases are still before the courts. The effectiveness of this legislation is 
discussed in the following Chapter 5 which discusses ideas for further 
government measures. 


Foreign Influence Transparency Scheme Act 2018 

4.14 The Foreign Influence Transparency Scheme Act 2018 (Transparency scheme) is 
managed by the Attorney-General's Department. The scheme's stated goal is to 
‘provide the public with visibility of the nature, level and extent of foreign 
influence on Australia's government and politics’, which is done via requiring 
individuals and entitles to register certain activities under the scheme if they are 
taken on behalf of a foreign principal. 


4.15 Under the Transparency scheme, a foreign principal includes a foreign 
government, a foreign political organisation, a foreign government related 
entity and a foreign government related individual. Registerable activities 
include parliamentary lobbying, general political lobbying, communications 
activities and disbursement activities (the payment of money or things of 
value).® 


4.16 ASIO has stated the two recent changes—the Espionage Act and Transparency 

scheme—have assisted in the fight to counter foreign interference in Australia: 
The passage of espionage and foreign interference (EFI) legislation has 
proven a valuable tool to ASIO and partners in preventing threats posed by 
foreign intelligence services (FIS) and their proxies. The legislation, coupled 
with operational work, caused some intelligence services to reassess the 
risks associated with conducting clandestine foreign intelligence operations 
in or against Australia, and—in some cases—they ceased activities. 


We assess that the legislation also contributed to some FIS more openly 
declaring their intelligence presence and activities in Australia. This 
informed our assessments, and improved our understanding of the EFI 
threat in Australia, enabling us to direct our efforts towards mitigating 
highest harm activities.° 


4.17 The Parliamentary Joint Committee on Intelligence and Security is currently 


undertaking a review into the operation, effectiveness and implications of the 
Transparency scheme which commenced on 6 February 2021. 


Online Safety Act 2021 

418 On 23 July 2021, the Online Safety Bill 2021 and Online Safety 
(Transitional Provisions and Consequential Amendments) Bill 2021 were 
enacted. They retained and replicated certain provisions in the 


8 Attorney-General’s Department, Foreign Influence Transparency Scheme, 


www.ag.gov.au/integrity/foreign-influence-transparency-scheme (accessed 26 April 2023). See also 
Attorney General’s Department, ‘Foreign Influence Transparency Scheme commences today’, 
Media Release, 10 December 2018. 


? Australian Security Intelligence Organisation, Annual Report 2019-20, p. 42. 


54 


4.19 


Enhancing Online Safety Act 2015 and made consequential amendments to 
‘protect more Australians from harm, or risk of harm', including through 
schemes regulating the non-consensual sharing of intimate images, online 
complaints, complaints-based removal notices and compliance requirements, 
and including app distribution services and internet search engine services into 
the remit of the new online content scheme. 


Significantly, the amendments also gave the eSafety Commissioner (outlined in 
greater detail below) powers to request or require internet service providers to 
disable access to material depicting, promoting, inciting or instructing in 
abhorrent violent conduct for time-limited periods in crisis situations. 1 


Privacy Act 1998 


4.20 


The Privacy Act 1988 (Privacy Act) is the principal piece of Australian legislation 
protecting the handling of personal information about individuals, including 
the collection, use, storage and disclosure of personal information in the federal 
public sector and in the private sector. The Attorney-General’s Department is 
conducting a review into the Privacy Act, which is discussed in greater detail 
later in this chapter. 


Government counter-interference entities 


4.21 


The following visualisation of the Australian Government's network for 
countering foreign interference maps the responsibilities and connections 
between departments and agencies. Further information about the participants 
and specific initiatives is on following pages. 


Counter Foreign Interference Strategy 


4.22 


Developed by the Department of Home Affairs (Home Affairs), the aim of the 
Counter Foreign Interference Strategy (CFI strategy) is to protect Australia's 
sovereignty, values and national interests from foreign interference. The CFI 
strategy includes five pillars aimed at enhancing capability, engaging with 
at-risk sectors, deterring perpetrators, defending against acts of foreign 
interference, and enforcing counter foreign interference laws." A summary of 
the CFI strategy is published on the Home Affairs website, but further details 
are not publicly available. 


10 The Hon Paul Fletcher MP, Minister for Communications, Urban Infrastructure, Cities and the Arts, 
House of Representatives Hansard, 24 February 2021, p. 1785. 


11 Department of Home Affairs, Australia’s Counter Foreign Interference Strategy, 


www.homeaffairs.gov.au/about-us/our-portfolios/national-security/countering-foreign- 


interference/cfi-strategy (accessed 17 February 2023). 


55 


Figure 4.1 Counter foreign interference network 


Aust Human 


National Rights 
Emergency Commiss. 
Mgmt Agency + Investigation 
+ National * Conciliation ; . 
Security + Education University 
Hotline FI Taskforce 


+ Guidelines 


OAIC 
ASIO Eo 
aie information 
+ Intelligence policy 
collection AFP + Advice 
“Advice + Intelligence + DP-Reg 
+ Investigations Collection i 
+ Community + Investigations & 
liaison enforcement 
+ CFI Taskforce + Advice 


+ Community liaison 
+ Joint Policing 

Cybercrime Coord 
Centre 


+ Intelligence 
collection 

+ Advice 

* Technology 
solutions 

+ Australian Cyber 


Security Centre 
EA W ffice of Ntnt 
y Intelligence 
AGO ~ Q + Intelligence 


+ Intelligence A assessment & 


A RK] A 
Collection : analysis 
Şi Counter Foreign seS 
Interference through advice 
š P + Leadershi| 
Social Media Network ae 


* Online content 
regulation 

+ Office of the 
esafety 


Commissioner 


eSafety 


Commiss. 

+ Regulation + Intelligence 
+ Investigation Collection 

+ Education 


+ Elections 

+ EIAT & Board 

+ Disinformation 
register 


+ Investigations 
& enforcement 

+ Advice 

+ Digital platform 

services 


DIGI 


+ Industry Code 
of practice on 
disinformation 
and 
misinformation 


Known participants and networks in the 
Australian Government's CFI network, in the 


context of social media—March 2023 
Prepared by the Foreign Interference Through 
Social Media committee secretariat 


56 


Home Affairs 
4.23 As well as participating in taskforces and other initiatives described below, 


Home Affairs advised the committee of broader activities it undertakes in 
relation to foreign interference. 


4.24 Home Affairs submitted that it engages ‘with a range of international partners 


through a variety of bilateral and multilateral forums to share information and 
exchange policy best practice approaches to counter foreign interference and 
malign information activities’. Home Affairs further submitted that this 
engagement ‘informs Australia’s domestic policies and legislative frameworks 
to protect Australian interests from hostile state actor activities’. However, no 
specific information was given on which international fora it participates in, nor 
which specific policies were adopted from overseas best practice. 


4.25 Home Affairs noted that it uses an integrated model to counter misinformation 


and disinformation online, particularly promoting Australian values and 
Australia’s inclusive national identity, but gain, did not provide anything 
specific as to whether it follows similar counter-tactics as outlined in Chapter 3 
on international approaches, such as using the DISARM or other agreed 
frameworks." 


National Counter Foreign Interference Coordinator 
4.26 The inaugural National Counter Foreign Interference Coordinator (NCFIC), 


Mr Chris Teal, was appointed in 2018 to work across government and 
non-government sectors to strengthen arrangements to counter foreign 
interference. The NCFIC administers the CFI strategy and is supported by the 
Counter Foreign Interference Coordination Centre (CFICC)." 


Counter Foreign Interference Coordination Centre 


4.27 The Home Affairs CFICC coordinates all Australian Government responses to 


foreign interference, including through the CFI strategy, outreach efforts and 
advice, engagement with culturally and linguistically diverse (CALD) 
communities, and engagement with international and regional partners." 


4.28 CFICC Partnership teams located in all states and territories also work closely 


with communities, state/territory governments, police and national security 


Department of Home Affairs, Submission 1, p. 4. 
Department of Home Affairs, Submission 1, p. 4. 


Department of Home Affairs, National Counter Foreign Interference Coordinator, 


www.homeaffairs.gov.au/about-us/our-portfolios/national-security/countering-foreign- 
interference/cfi-coordinator (accessed 17 February 2023). 


Department of Home Affairs, Countering foreign interference, www.homeaffairs.gov.au/about- 
us/our-portfolios/national-security/countering-foreign-interference (accessed 18 January 2023). 


57 


agencies to build community awareness of, and resilience to, the threat of 
foreign interference. '° 


Counter Foreign Interference Taskforce 
4.29 Established in 2020 and lead by ASIO, the CFI Taskforce, discovers, disrupts and 


investigates foreign interference activity, including through investigations and 
enforcement activity. Membership includes ASIO, Home Affairs and the AFP.” 
ASIO noted that the taskforce is ‘designed to mitigate harm and disrupt the 
threat of espionage and foreign interference by leveraging the unique 
capabilities of our intelligence and law enforcement agencies and it uses a range 
of mechanisms such as ‘intelligence operations, law enforcement activity and 
prosecutions under the Espionage and Foreign Interference Legislation and the 
Foreign Influence Transparency Scheme, visa cancellations, and financial 
disruptions’."* 


4.30 The CFICC confirmed with the committee that it is not a member of the 


CFI Taskforce because ‘structure is an operational activity, and Home Affairs 
does not undertake the operational investigative aspects’ however it was noted 
that the CFICC has ‘responsibility for the oversight board for the taskforce and 
engage[s] with them to inform policy and to work with them on policy aspects 
of investigations’ .'° 


Australian Cyber Security Centre 
4.31 The Australian Cyber Security Centre leads the Australian Government's efforts 


20 


to improve cyber security by providing advice, alerts and information about 
cyber threats and monitoring threats globally and developing solutions, 
including in relation to foreign interference and disinformation. The Australian 
Government has committed to 10 years of investment in the Australian Signals 
Directorate (ASD)—known as REDSPICE—to improve cyber defences from 
2022-23. 


Department of Home Affairs, Countering foreign interference in communities, 
www.homeaffairs.gov.au/about-us/our-portfolios/national-security/countering-foreign- 
interference/in-communities (accessed 21 February 2023); Senate Standing References Committee 


on Foreign Affairs, Defence and Trade, Human rights implications of recent violence in Iran final report, 
February 2023, p. 47. 


Department of Home Affairs, Countering foreign interference. 
Australian Security Intelligence Organisation, Submission 2, p. 6. 


Ms Sally Pfeiffer, Acting First Assistant Secretary, Counter Foreign Interference, Department of 
Home Affairs, Committee Hansard, 12 July 2023, p. 12. 


Australian Cyber Security Centre, Australian Signals Directorate, Annual cyber threat report July 
2021-June 2022, p. 11. 


58 


Cyber and Infrastructure Security Centre 
4.32 The Cyber and Infrastructure Security Centre of Home Affairs actively assists 


Australian critical infrastructure owners and operators to understand the risk 
environment and meet their cyber-related regulatory requirements, in addition 
to its own regulatory requirements. It works in partnership with government, 
industry and community. 


Foreign Influence Transparency Scheme 
4.33 The Foreign Influence Transparency Scheme commenced on 10 December 2018. 


The purpose of the scheme is to provide the public with visibility of the nature, 
level and extent of foreign influence (rather than interference) on Australia's 
government and politics, including through registration of individuals and 
entities, foreign principals, and registerable activities, with additional 
obligations during voting periods.”! 


4.34 Under the scheme, communications activities such as those conducted on social 


media need to be registered if they are undertaken in Australia on behalf of a 
foreign principal for the purpose of political or government influence. 
The Attorney-General's Department advised that all scheme registrants met 
their obligations under the act in relation to the 2022 federal election. 


Community Liaison Officer network 


4.35 The Home Affairs network of Regional Directors and Community Liaison 


Officers engage with a wide range of cultural, religious and ethnic community 
stakeholders around Australia, to 'support the communication of official 
information to CALD communities, and provides a mechanism for community 
members to share information about their priorities, concerns, and the impact 
of government policies and programs on their communities’.” 


National Security Hotline 
4.36 The National Security Hotline, administered by the National Emergency 


21 


22 


23 


Management Agency, takes reports of suspicious behaviour in relation to 
terrorism and foreign interference, including where people are ‘being 
intimidated or harassed by someone linked to a foreign government’ or ‘coerced 
to return to their home country’. 


Attorney-General's Department, Foreign Influence Transparency Scheme, 
www.ag.gov.au/integrity/foreign-influence-transparency-scheme (accessed 17 February 2023); 
Attorney-General's Department, Submission 13: Foreign Interference through Social Media inquiry (46th 
Parliament), p. 9. 


Attorney-General's Department, Submission 13: Foreign Interference through Social Media inquiry (46th 
Parliament), p. 8. 


Australian Government, Australian National Security: report suspicious behaviour, 
www.nationalsecurity.gov.au/what-can-i-do/report-suspicious-behaviour, 
(accessed 16 February 2023). 


59 


University Foreign Interference Taskforce 
4.37 The University Foreign Interference Taskforce (UFIT) was established in 2019, 


4.38 


to support and build resilience against foreign interference in universities. The 
UFIT Steering Group ‘primary conduit for all university and Government 
counter foreign interference related activities’. In 2019, UFIT released the 
Guidelines to Counter Foreign Interference in the Australian University Sector, 
with an update released in November 2021. 


Evidence received during the Inquiry into national security risks affecting the 
Australian higher education and research sector suggested that the taskforce is 
unique amongst Five Eyes Plus nations, and that it has been a highly successful 
collaborative approach which has been mirrored in other jurisdictions.” 


Strengthening Democracy Taskforce 


4.39 


Announced on 8 December 2022, the Strengthening Democracy Taskforce, 
housed within Home Affairs, aims to bolster Australia's democratic resilience 
and enhance trust among citizens, and between citizens and governments. 
The taskforce will work in partnership with Australian civil society 
organisations to deliver a practical agenda for sustaining and strengthening our 
democratic resilience. The taskforce will work closely with the newly 
established National Resilience Taskforce ‘noting Australia's democratic 
resilience underpins our national resilience’. 


Election Integrity Taskforce 


4.40 


4.41 


24 


The Election Integrity Taskforce is comprised of a range of 
Australian Government agencies who provide specialist support to the 
Australian Electoral Commission (AEC) to support election integrity including 
cyber security and disinformation. The taskforce supports various electoral 
events, including federal by-elections and State and territory elections. The AEC 
submitted that ‘Taskforce agencies did not identify any foreign interference, or 
any other interference, that compromised the delivery of the 2022 federal 
election’ .”” 


However, David Robinson of Internet 2.0 expressed scepticism on this. 
He pointed to a study of social media commentary after the 2021 coup in 
Myanmar, where the Pentagon’s social media accounts were hit with 700 000 


Department of Education, University Foreign Interference Taskforce, Guidelines to Counter Foreign 


Interference in the Australian University Sector, 17 November 2021. 


25 Joint Standing Committee on Intelligence and Security, Inquiry into national security risks affecting the 
Australian higher education and research sector, March 2022, pp. 89-93 and 105-106. 


2% Department of Home Affairs, Submission 1, p. 5. See also The Hon Clare O'Neil MP, Minister For 
Home Affairs, Strengthening democracy taskforce, 8 December 2022. 


27 


Australian Electoral Commission, Submission 8, p. 2. 


60 


posts related to the coup. Social media companies and providers tracked the 
authenticity of the debate and found that it was authentic behaviour. However, 
when Internet 2.0 studied the data from a mathematical analysis perspective, 
they were easily able to identify an inauthentic campaign. In relation to the 
safety of Australian elections from CIB, Mr Robinson stated that until someone 
had done similar analysis ‘I don't think you can say either way’.* 


Code of practice on misinformation and disinformation 


4.42 


4.43 


4.44 


In December 2019, the Australian Government requested that major digital 
platforms in Australia develop a voluntary code of practice to address online 
disinformation and news quality concerns. 


In February 2021, Digital Industry Group Inc (DIGI) published the 
Australian Code of Practice on Disinformation and Misinformation (DIGI code) with 
8 signatories: Adobe, Apple, Google, Meta, Microsoft, Redbubble, TikTok and 
Twitter. The DIGI code aimed to provide safeguards against harms from the 
spread of mis and disinformation on digital platforms. The DIGI code was then 
updated in October 2022 with changes to the code's governance.” 


The objectives of the DIGI code are: 


(a) Provide safeguards against harms that arise from mis and disinformation. 

(b) Disrupt advertising and monetisation incentives for mis and 
disinformation. 

(c) Work to ensure the integrity and security of services and products 
delivered by digital platforms. 

(d) Empower consumers to make better informed choices of digital content. 

(e) Improve public awareness of the source of political advertising carried on 
digital platforms. 

(f) Strengthen public understanding of mis and disinformation through 
support of strategic research. 

(g) Signatories publicise measures they take to combat mis and 
disinformation. 30 


Australian Communications and Media Authority 


4.45 


The Australian Communications and Media Authority (ACMA) is the 
independent statutory authority responsible for the regulation of broadcasting, 
radiocommunications and telecommunications in Australia. The ACMA's remit 


2 Mr David Robinson, Director, Internet 2.0, Committee Hansard, 20 April 2023, p. 36. The AEC was 
not asked by the committee whether it had conducted a similar mathematical analysis. 


29 


Digital Industry Group Inc, Australian Code of Practice on Disinformation and Misinformation, 


22 February 2021 and Digital Industry Group Inc, Australian Code of Practice on Disinformation and 
Misinformation, updated 11 October 2021. 


30 


Digital Industry Group Inc, Australian Code of Practice on Disinformation and Misinformation, updated 


11 October 2021, pp. 10-15. 


61 


also includes aspects of online content regulation; relevantly, the ACMA 
monitors digital platforms' activities under the DIGI code, including in response 
to coordinated campaigns by foreign actors.*! 


4.46 InJune 2021, the ACMA finalised A report to government on the adequacy of digital 


platforms’ disinformation and news quality measures. The ACMA found the scope 
of the DIGI code is limited by the threshold where both 'serious' and 'imminent' 
harm must be reached before action is required. 'The effect of this is that 
signatories could comply with the code without having to take any action on the 
type of information which can, over time, contribute to a range of chronic harms, 
such as reductions in community cohesion and a lessening of trust in public 
institutions.’ The DIGI code was subsequently updated by signatories, to 
change the definition of harm to a threshold of ‘serious and credible’ threat of 
harm.” 


4.47 The ACMA found challenges in obtaining relevant data on platform actions in 


Australia and recommended: 


e That the ACMA be vested with formal information-gathering powers 
(including powers to make record-keeping rules) to incentivise greater 
platform transparency and improve access to data on the effectiveness of 
measures to address mis and disinformation in Australia. 

e The ACMA be vested with reserve regulatory powers in relation to digital 
platforms — such as code registration powers and the ability to set 
standards. 

e A misinformation and disinformation Action Group be established to 
support collaboration and information-sharing between digital platforms, 
government agencies, researchers and non-government organisations on 
issues relating to mis and disinformation.“ 


4.48 The Australian Human Rights Commission (AHRC) also noted that although 


31 


32 


33 


34 


35 


platforms are publishing transparency reports under the DIGI code, and the 
code itself was updated in December 2022, ‘none of these existing measures are 
specifically focused on the question of foreign interference through social 
media, or the particular strategic risks posed to Australia through these 
activities’.* 


Australian Communications and Media Authority, Submission 6, p. 1. 


Australian Communications and Media Authority, A report to government on the adequacy of digital 
platforms’ disinformation and news quality measures (Report on digital platform measures), p. 3. 


Digital Industry Group Inc, Submission 36, p. 4. 
Australian Communications and Media Authority, Report on digital platform measures, p. 4-5. 


Australian Human Rights Commission, Submission 9, p. 7. 


62 


4.49 


On 21 March 2022 the Australian Government announced it would consult on 
proposals to introduce legislation in the second half of 2022 to combat harmful 
online mis and disinformation. These new powers for the ACMA have been 
proposed via an exposure draft of new legislation, which is discussed in greater 
detail later in this chapter. 


eSafety Commissioner 


4.50 


The eSafety Commissioner is Australia's independent regulator for online safety 
with a role to help safeguard Australians at risk from online harms and to 
promote safer, more positive online experiences. While foreign interference is 
not a matter which falls directly within the remit of the eSafety Commissioner, 
this activity intersects with two of its functions, namely its role in promoting 
‘Safety by Design’ principles and compliance with the government's 
‘Basic Online Safety Expectations’.*” 


DP-REG 


4.51 


4.52 


The Digital Platform Regulators Forum (DP-REG) was established in early 2022 
to facilitate better coordination across government on digital platform 
regulation. It includes the ACMA, the Australian Competition and Consumer 
Commission, the Office of the eSafety Commissioner, and the Office of the 
Australian Information Commissioner. 


DP-REG’s strategic priorities for 2022—23 include a focus on the impact of 
algorithms, efforts to improve transparency of digital platforms’ activities and 
how they are protecting users from potential harm—including from mis and 
disinformation—and increased collaboration and capacity building between 
members.** 


Recent policy responses and initiatives 


Budget 2023-24 


4.53 


On 9 May 2023, the Australian Government announced a range of measures to 
improve privacy, digital safety, cybersecurity and development of critical 
technology industries. There were a number of key budget which are likely to 
directly impact on matters relating to foreign interference through social media, 
including: 


e funding to progress the government's response to the Privacy Act review 
($0.9 million over two years); 


3% Department of Infrastructure, Transport, Regional Development, Communications and the Arts, 


Media release: New disinformation laws, 21 March 2022. 


37 eSafety Commissioner, Submission 10, p. 1. 


38 Australian Communications and Media Authority, Submission 6, p. 4. 


63 


e funding to help combat scams and mis and disinformation, including: 


— funding for the ACMA to resource the Office of the eSafety 
Commissioner — $134.1 million over four years ($33.7 million per year 
ongoing, in addition to the existing base funding of $10.3 million per 
annum ongoing). This will be partly met by existing departmental 
resourcing and be used for a variety of programs including ‘enhanced 
educational, outreach and investigatory activities’; 

— funding for the ACMA for the implementation of ‘new powers to hold 
digital platforms to account and improve efforts to combat harmful 
misinformation and disinformation in Australia'—$7.9 million over four 
years; 


e establishment of the Coordinator for Cyber Security within Home A ffairs— 
$46.6 million over four years, then $11.8 million per year ongoing. Noting 
this appears to be funding redirected from ASD rather than new funding; 
and 

* support for local news and media and promotion of media literacy, 
including $2.5 million over two years 'to build media literacy in culturally 
and linguistically diverse communities. This funding will be used by the 
government to: 

... partner with the Federation of Ethnic Communities’ Council of Australia 
(FECCA) to support media literacy in culturally and linguistically diverse 
(CALD) communities. This partnership aims to empower multicultural 
communities to combat harms associated with the proliferation of deceptive 


information including mis and disinformation, and support improved 
economic and civic participation.’ 


Privacy Act amendments and review 
4.54 The first interim report of the 46th Parliament inquiry into foreign interference 


39 


40 


41 


discussed potential amendments to the Privacy Act, including the 'introduction 
of a binding online privacy code for social media and certain other online 
platforms'.® However, ultimately the Privacy Legislation Amendment 
(Enforcement and Other Measures) Bill 2022 passed into law on 
12 December 2022 without introducing such a requirement.“ Rather, the bill 
increased penalties for serious or repeated interferences with privacy, enhanced 
enforcement powers for the Australian Information Commissioner, and 


Australian Government, Budget 2023-24: Budget Measures, Budget Paper No. 2, p. 183; The Hon 
Michelle Rowland MP, Minister for Communications, 'Budget 2023-24: Connecting, informing and 
protecting Australians', Media release, 9 May 2023. 


Attorney-General's Department, Online Privacy Bill Exposure Draft. 


Parliament of Australia, Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022. 


64 


4.55 


4.56 


4.57 


4.58 


4.59 


provided the commissioner and the ACMA with greater information sharing 
powers.” 


In 2020, following the initial Australian Competition and Consumer 
Commission digital platforms inquiry of 2019, the Attorney-General 
commenced a review of the Privacy Act, releasing a review report in 
February 2023.* 


Reforms proposed by the report include stronger protections for personal 
information, greater transparency and control for individuals over their 
information, and more enforcement and _ redress mechanisms.“ 
The Attorney-General's Department informed the committee that ‘the general 
theme around the review itself was to conduct an uplift in terms of individuals' 
control over their personal data and how it's used, and also generally awareness 
raising and transparency initiatives’. 


The report included discussion about the scope for political disinformation in 
relation to political targeting and microtargeting, including the 'involvement of 
foreign interests in political communication’ and the possibility of negative 
impacts on democracy. Many submitters to the review referenced the 
Cambridge Analytica matter and ‘expressed concern about whether the political 
exemption may allow such an incident in Australia’. 


Discussion also considered the security of personal information held by political 
parties and the potential for this information to be targeted by foreign 
interference in elections, with the proposal that political entities be required to 
take 'reasonable steps to protect personal information'.”” 


Disinformation was also considered in the report the context of direct and 
targeted marketing and serious negative impacts which this can cause, 'for 
example by contributing to disinformation campaigns or by discriminating 
against certain groups’ and 'risks undermining other public interests, including 
the integrity of the democratic electoral process'.* 


42 Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022 Explanatory Memorandum, 
2022, p. 2; Attorney-General's Department, Submission 25, p. 7. 


48 Attorney-General's Department, Privacy, www.ag.gov.au/rights-and-protections/privacy 
(accessed 17 July 2023); Attorney-General's Department, Privacy Act Review — Report on a page. 


44 Attorney-General's Department, Privacy Act Review Report 2022, pp. 5, 7 and 12-14; 
Attorney-General's Department, Submission 25, p. 8. 


3 Ms Sarah Chidgey, Deputy Secretary, National Security and Criminal Justice, Attorney-General's 
Department, Committee Hansard, 12 July 2023, p. 22. 


46 Attorney-General's Department, Privacy Act Review Report 2022, pp. 75-81. 


47 Attorney-General's Department, Privacy Act Review Report 2022, pp. 82-83. 


48 Attorney-General's Department, Privacy Act Review Report 2022, pp. 200 and 210. 


65 


4.60 The review report also examined international data flows, specifically 


mentioning concerns raised in relation to social media platform TikTok. 
The report considered options for regulating privacy for foreign organisations 
or small business operations which have an ‘Australian link’ and allowing for 
the flow of information overseas while ensuring privacy is protected including 
the Cross-Border Privacy Rules or a domestic certification scheme. However, the 
report noted that some 'submissions noted that personal information transferred 
overseas could potentially be accessed by overseas governments, and that it 
could be more difficult for individuals to enforce privacy rights and access 
justice for overseas privacy infringements’. 


4.61 The Attorney-General’s Department sought feedback by 31 March 2023 to its 


review report, noting that feedback would ‘inform the Australian Government’s 
response to this report to ensure that any reforms the Australian Government 
implements are balanced and effective’. There is no information available on any 
timeline for proposed changes to the Privacy Act.» 


4.62 However, the United States Federal Communications Commissioner, 


Mr Brendan Carr, expressed some doubt that privacy protections would be 
wholly effective. Commissioner Carr noted that Europe has ‘gold standard’ 
privacy protections, but is still finding it necessary to ban apps such as TikTok: 


If privacy protections were enough to address TikTok then we wouldn't see 
these concerns existing today in Europe. So privacy is important, but, when 
we're dealing with a company with a history of misrepresentations, because 
of their conduct, we do not have a baseline level of trust. Privacy protection 
isn't tailored to address those national security threats.*! 


AEC activities 
4.63 As noted above, the AEC is a member of the Election Integrity Taskforce and 


has undertaken a number of activities designed to protect election-related 
activity in Australia. However, the AEC noted that while the Electoral Act 1918 
does ‘require electoral matter to be properly authorised to inform voters of the 
source of communication’ it ‘does not regulate truth in electoral 
communication’.* In other words, a person or organisation can provide false 
information, but they must put their name to it. 


4.64 The AEC noted that as part of its integrity work, it has launched a ‘purpose-built 


49 


50 


51 


52 


Command Centre for rapid and coordinated incident response, including a 


Attorney-General's Department, Privacy Act Review Report 2022, pp. 242 and 247-248. 


Attorney-General’s Department, Government response to the Privacy Act Review Report, 
https://consultations.ag.gov.au/integrity/privacy-act-review-report/ (accessed 17 July 2023). 


Mr Brendan Carr, Commissioner, United States Federal Communications Commission, Committee 
Hansard, 20 April 2023, p. 8. 


Australian Electoral Commission, Submission 8, p. 2. 


66 


4.65 


dedicated media hub to quickly respond to electoral disinformation’ as well as 
a ‘Disinformation Register to list and debunk electoral process disinformation’. 
The AEC further noted it has developed effective working relationships with 
social media organisations, including a signed public agreement with Meta, 
Twitter, Google, Microsoft and TikTok. However, CyberCX expressed doubt 
that any department or agency ‘has the capability or authority to lead in relation 
to a social media disinformation campaign related to political parties, 
candidates or policies’.™ 


Dr Andrew Dowse of RAND Australia noted that an unintended consequence 
of election blackout periods for mainstream media, was that it drove people to 
social media where there was less chance of appropriately moderated 
information, and this should be considered.» 


Stop and consider campaign 


4.66 


4.67 


4.68 


The AEC managed the Stop and Consider campaign during the 2022 federal 
election to help voters to cut through disinformation and spin messages they 
may receive. 


Information was distributed to voters primarily via social media feeds and 
through digital displays with translated material distributed through 
CALD audiences. The AEC also operated a disinformation register listing 
prominent pieces of disinformation regarding the election process. 


Chapter 7 contains more in-depth discussion around these education and digital 
literacy campaigns run by the AEC and other entities. 


Voice referendum 


4.69 


The AEC has also noted work being done on the proposed referendum to be 
held later in 2023, to help prevent the spread of disinformation. The AEC noted 
that due to the long time since the last referendum in 1999, there are 
approximately 7.4 million people who will never have voted in a referendum 
before and this lack of experience ‘coupled with the ever-increasing digital 
consumption of information, means social media platforms will undoubtedly 
play a key role for electors seeking information’. 


53 Australian Electoral Commission, Submission 8, pp. 2-3. 


54 CyberCX, Submission 16, p. 7. 


5 Dr Andrew Dowse, Director, RAND Australia, Committee Hansard, 20 April 2023, p. 29. 


56 Australian Electoral Commission, 


‘ 


AEC launches campaign to combat disinformation’, 


Media release, 12 April 2022. 


°” Australian Electoral Commission, Submission 8, p. 1. 


67 


Home Affairs review of foreign interference through social media 

4.70 Home Affairs was tasked by the Home Affairs Minister in September 2022, with 
undertaking a review into Foreign Interference through Social Media 
Applications. The review was asked to consider all options to address data 
security risks, as well as disinformation concerns as they relate to social media 
platforms and was delivered to the Minister for Home Affairs on 16 March 2023 
and is not expected to be publicly released.* 


4.71 CyberCX noted that this review was expected to look at data harvesting by 
TikTok and other social media platforms, but noted it is unclear whether 
platforms’ content moderation and algorithm practices were also reviewed.” 


TikTok on Australian Government devices 

4.72 Following the delivery of the Home Affairs review outlined above, on 
4 April 2023. TikTok was banned from on devices issued by 
Australian Government departments and agencies. The ban is discussed in 
greater detail in Chapter 6. 


Community outreach 

4.73 On 14 February 2023, the Minister for Home Affairs announced a new 
community outreach program to be coordinated by Home Affairs and ASIO. 
The program will identify individuals within the Australian community who 
might be targets of foreign interference and design and deliver a program to 
proactively help them understand what foreign interference is, how they can 
respond, and what the government can do to protect them.” 


4.74 Home Affairs advised the committee on 12 July 2023, that this program has 
begun and is ‘looking to identify communities that we think are at risk and to 
then proactively engage with them and seek opportunities to provide them 
information and make sure that we're engaging in understanding their 
concerns’. Home Affairs advised it had not been allocated any new resources for 
this program, which it had already been undertaking, simply not at this scale.“ 


4.75 On 27 February 2023, the AFP announced the launch of an education campaign 
to help CALD communities understand what foreign interference is, how it 
manifests itself and where victims can report instances and seek assistance. 


58 Department of Home Affairs, Submission 1, p. 5 and Mr Peter Anstee, Acting First Assistant 
Secretary, Department of Home Affairs, Committee Hansard, 12 July 2023, p. 2. 


5 CyberCX, Submission 16, p. 7. 


60 The Hon Clare O'Neil MP, Minister for Home Affairs, Minister for Home Affairs, Foreign interference 
in Australia - ANU address, 14 February 2023. 


& Ms Sally Pfeiffer, Department of Home Affairs, Committee Hansard, 12 July 2023, p. 13. 


68 


It will include meetings between AFP community liaison teams, CALD groups 
and religious leaders, and a factsheet translated into more than 30 languages. 


National Office for Cyber Security 
4.76 On 27 February 2023, the Prime Minister and the Minister for Home Affairs 


jointly announced the creation of a new National Office for Cyber Security, to 
help mitigate the impact of major cyber incidents. The office will help establish 
a strategic and structured approach to cyber security across government, and 
help to manage cyber incidents in a seamless and strategic way across 
government. The Australian Government is also proposing a discussion paper 
to improve the function of relevant laws and policies. 


Data Security Action Plan 
4.77 Under current development, Australia's first Data Security Action Plan is a key 


initiative under the Cyber Security Strategy 2023-2030, that will seek to strengthen 
data security policy settings across government and the broader economy, 
including consideration of storage settings of domestic and international data 
and whether they adequately promote privacy, security and transparency. 


4.78 From 6 April to 24 June 2022, Home Affairs undertook consultation and received 


62 


63 


64 


65 


81 submissions on the plan. As of 10 July 2023, Home Affairs is currently 
developing the final plan. 


Australian Federal Police, ‘AFP launches new resource to help combat foreign interference’, Media 
release, 27 February 2023. 


CyberSecurity Connect, Federal government to stand up new National Office for Cyber Security, 
27 February 2023. 


Department of Home Affairs, Submission 1, p. 5. 


Department of Home Affairs, Uplifting data security across Australia, www.homeaffairs.gov.au/ 
reports-and-publications/submissions-and-discussion-papers/data-security 
(accessed 10 July 2023). 


5.1 


5.2 


5.3 


5.4 


5.5 


5.6 


L 


2 


Chapter 5 
Government: ideas for action 


The Australian Security Intelligence Organisation (ASIO) described the threat of 
foreign interference as being at the highest level in Australia’s history.’ 


Throughout this inquiry, the Select Committee on Foreign Interference through 
Social Media (committee) received advice from expert organisations, members 
of the community, government agencies and the platforms themselves on steps 
which are urgently required to improve the countermeasures taken against 
foreign interference through social media, and to protect Australia’s democratic 
resilience. 


A key theme emerged among the recommendations: the need for cross-sector, 
cross-border alliances, where government, platforms and civil society work 
together to tackle the threat of foreign interference. These recommendations are 
discussed in the next three chapters. While recognising the inter-connectedness 
of many of these recommendations, they have been broken down by who would 
be the lead entity for each recommendation: government, platforms or civil 
society. This chapter will outline proposals for action where government would 
be either the sole, or lead entity. 


The committee heard a common message from a range of experts and people 
from impacted communities consistently confirming that not enough was being 
done by government to address foreign interference and coordinated 
inauthentic behaviour (CIB) through social media. 


CyberCX submitted a range of recommendations and noted that it believes the 
Australian Government’s responses have not kept pace with the nature and 
scale of the risks of foreign interference through social media. 


The Australian Strategic Policy Institute (ASPI) made a similar overall 
observation, and advised: 


Today, our key recommendation for the Australian government is it needs 
to lead on the issue and not rely on social media platforms and civil society 
fact checkers to counter disinformation. This includes incorporating counter 
foreign interference through social media into a broader national security 
strategy and mandating platforms to disclose covert state backed influence 
operations...The ongoing issue of foreign interference through social media 


Lisa Visentin and Matthew Knott, ‘”It feels like hand-to-hand combat”: ASIO boss warns on spy 
hives, foreign interference’, Sydney Morning Herald, 21 February 2023. 


CyberCX, Submission 16, p. 7. 


69 


70 


requires a whole-of-government and proactive strategy to protect the 
integrity of our democracy and the wellbeing of our citizens.° 


Lead agency 


5.7 There have long been concerns expressed by the private sector expert 
community on the ‘lack of clarity on which parts of the Australian Government 
have leadership and authority in protecting which parts of Australia’s 
information environment—the public sector, the private sector and individual 


citizens— from interference by foreign actors acting with malicious intent’. 


5.8 These concerns were repeated by many submitters and witnesses, who noted 
that although there were numerous specialist taskforces (outlined in Chapter 4), 
a single lead agency to take core responsibility is needed, while ensuring 


appropriate coordination and collaboration with other agencies, platforms and 


private sector experts. 


5.9 Indeed, the previous report of this committee also identified the absence of a 
single, lead focal point for cyber-enabled foreign interference. This problem has 
been a long-standing one, across multiple governments. It should be noted that 
submitters acknowledge a need for a whole of government approach, not 


replacement of such an approach with one lead agency. 


5.10 CyberCX recommended: 


A single lead entity is needed to coordinate government policy and action 
on cyber-enabled interference. Importantly, it will also create a clear 
‘one-stop-shop’ for citizens and private sector stakeholders to report, and 
seek advice about, foreign interference risk linked to social media.* 


5.11 ASPI also recommended the government take a stronger lead on this issue: 


...to ensure clarity on which government institutions are responsible for 
dealing with cyber-enabled foreign interference from both an operational 
and policy perspective. Currently, uncertainty as to whom in government 
has responsibility is creating a disincentive for victims to report while not 
providing disincentives to perpetrators to cease their malicious activity.° 


5.12 ASPI further recommended that ‘cyber-enabled foreign interference should be 


incorporated into broader cybersecurity and national security strategies’.’ 


3 Mr Albert Zhang, Analyst, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, 


p. 18. 


4 Danielle Cave and Dr Jacob Wallis, ‘AUSMIN 2022: Cyber-enabled_ foreign interference’, 


The Strategist, 1 December 2022. 
5 CyberCX, Submission 16, p. 7. 


€ Australian Strategic Policy Institute, Submission 13, p. 12. See also: Mr Albert Zhang, Australian 


Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 21. 


7 Australian Strategic Policy Institute, Submission 13, p. 12. 


71 


5.13 


5.14 


The Australian Human Rights Commission (AHRC) noted: 


In order to address this specific risk, the Australian Government should 
establish a permanent whole-of-government taskforce dedicated to 
preventing and combating cyber-manipulation in Australia. The terms of 
reference for this taskforce should extend beyond those of the 
Electoral Integrity Assistance Taskforce to encompass not solely threats to 
the integrity of a federal election or electoral integrity, but threats to 
Australia’s democracy more broadly.® 


A joint submission from technical specialist University centres noted the 
complexity of the many varied government agencies and taskforces which have 
roles in this space, and noted that: 


...it is unclear what exactly each governmental body’s role is and whether 
foreign interference on social media falls within each body’s scope of 
concern. Moreover, there is often little information about how much 
progress these various governmental bodies have made in monitoring or 
mitigating disinformation. Compounding this complexity, there does not 
appear to be a single body responsible for coordinating the government's 
response to the risks posed to democracy online (whether it be through 
disinformation or other phenomena on social media and the internet more 
broadly). Nor is there a single point of contact for the public regarding these 
risks.? 


Standards-based regulation 


5.15 


5.16 


5.17 


The inquiry dove deeply into the issue of whether government should address 
the risks posed by specific platforms and applications by banning them, or 
whether a platform neutral approach should be taken to set standards that all 
platforms should meet. However, the committee noted there is a clear 
distinction between platforms which originate in authoritarian states rather than 
liberal democracies, with a specific set of risks attached, and that risk is 
discussed in the following chapter on platforms. ° 


More than one witness described the approach of banning specific platforms as 
‘whack a mole’, where dealing with risks platform by platform simply meant a 
new one would pop up to replace each banned platform. 


ASPI advised that an approach to use legislated standards rather than bans on 
individual applications was preferable but noted that ‘there's also a need for 
bespoke legislation that accepts the fact that there is a unique problem with 


8 Australian Human Rights Commission, Submission 9, p. 8. 


UNSW Allens Hub for Technology, Law and Innovation, Society on Social Implications of 


Technology and Deakin University Centre for Cyber Security Research and Innovation, 
Submission 19, p. 5. 


10 See: Dr William Stoltz, Private capacity, Committee Hansard, 20 April 2023, p. 38; Ms Lindsay 
Gorman, Senior Fellow for Emerging Technologies, Alliance for Securing Democracy, German 
Marshall Fund, Committee Hansard, 21 April 2023, p. 10. 


72 


social media apps that come from authoritarian countries’ and pointed to the 
United States RESTRICT Act as a step in the right direction." 


5.18 Ms Lindsay Gorman of the Alliance for Security Democracy also recommended 


an approach which outlines the safety standards expected of platforms and 
apps, but that also takes into account the additional risks inherent in apps based 
within authoritarian states: 


My first recommendation was to come up with this overarching framework 
that includes the threat of platforms from authoritarian regimes and really 
spells out what the concerns are. Is it scale? Is it the degree of ownership and 
influence? Is it the type of platform itself? ... I think there needs to be a much 
broader framework and a much clearer framework so that when 
authoritarian internet apps do come to democracies, as they inevitably will 
in open societies, we have a framework for addressing it, and we don't have 
to wait until it becomes this behemoth of an issue to deal with a specific 
platform. 12 


5.19 Ms Gorman pointed to the Prague proposals on 5G internet as a ‘fantastic 


starting point for this kind of legislative development which does identify 
countries of origin while also trying to promote standards that apply to any 
internet platform’. 


5.20 Ms Gorman further advised for separate regulation on AI generated content, 


because the ‘democratisation of the ability to create extremely realistic but 
completely fake content... increases avenues for propaganda [that is] designed 
to spoof and generate content that looks plausible, and sounds like it might be 
written by a human, but isn't necessarily true’. Ms Gorman expressed concern 
that ‘our knowledge base of what is actually true becomes at risk and our very 
trust in information becomes downgraded’. 


5.21 For example, Ms Gorman pointed to existing content authenticity frameworks 


such as watermarks, which could be mandated ‘so you can tell when an image 
has been manipulated and when it hasn't, and you can track the history of that 
image’ .!° 


5.22 The AHRC recommended the Australian Government ‘introduce transparent 


user-data privacy and user-data protection frameworks that apply to all social 


Mr Fergus Ryan, Analyst, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, 
p. 21. 


Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 10. 


Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 14. The 
Prague Proposals on Cyber Security of Emerging and Disruptive Technologies were introduced at the 
Prague 5G Security Conference in 2021. They promote strategic thinking about security of emerging 
and disruptive technologies in the context of national security. 


Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 11. 


Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 11. 


73 


5.23 


media and internet companies’ and further recommended that any company 
that ‘refuses to comply with such frameworks should not be able to operate in 
Australia’.16 


ASIO noted that social media ‘has benefited from an era of unprecedented 
connectivity with limited regulation, thus creating the conditions to allow 
disinformation and misinformation to proliferate and indeed flourish’ and 
further noted that there are few laws governing online activity and the 
extraterritorial nature of the activity means that attribution to a foreign power 
‘can be difficult to ascertain, even where such laws come into play’.!” 


Proportionality 


5.24 


5.25 


5.26 


5.27 


While calling for greater regulation of social media platforms to protect 
Australians from foreign interference, many expert organisations also noted the 
need for proportionality, whereby the solutions did not stray too far into the 
realm of curtailing the freedoms that are the bedrock of liberal democracies. 


The AHRC noted that ‘social media can be used for purposes that both 
strengthen or undermine Australia’s democracy and values’ and further 
advised: 
Striking the right balance between regulating online activities and 
protecting free expression is an ongoing challenge. While there is a clear 
need to combat misinformation and disinformation online, there is also a 
risk that in doing so different perspectives and controversial opinions may 
be targeted. While reasonable minds may differ on exactly where the line 
should be drawn, if we fail to ensure robust safeguards for freedom of 
expression online, then the very measures taken to combat misinformation 
and disinformation could themselves risk undermining Australia’s 
democracy and values.'® 


Mr Kenny Chiu, a former Canadian MP who had been subjected to foreign 
interference during an election also argued against ‘blunt tools’ and called for 
proportionality that will ‘protect what we have treasured and worked so hard 
for while at the same time countering the disinformation and interference that 
we are facing together—not just as Australians but also with other countries 
such as Canada, the UK and the US’. 


Human Rights Watch noted that it does not support bans because it wants to 
see free speech and freedom of expression, ‘but we want there to be credible 


16 Australian Human Rights Commission, Submission 9, p. 14. 


17 Australian Security Intelligence Organisation, Submission 2, pp. 4 and 5. 


18 Australian Human Rights Commission, Submission 9, pp. 3 and 8-9. 


Mr Kenny Chiu, Private capacity, Committee Hansard, 21 April 2023, p. 18. 


74 


5.28 


5.29 


news sources, and for people in these communities to be aware of these 
alternative news sources’ .?0 


Meta also argued in favour of regulation being considered ‘with regard to 
individual human rights, such as freedom of expression, freedom of speech, 
access to information and, of course, privacy’.” 


There was extensive discussion on the issue of censorship and this discussion is 
captured below in the section on the new proposed powers for the 
Australian Communications and Media Authority (ACMA). 


Proposed new powers for the Australian Communications and Media Authority 


5.30 


5.31 


5.32 


In June 2023, the Department of Infrastructure, Transport, Regional 
Development, Communications and the Arts (Department of Communications) 
released an exposure draft of the Communications Legislation Amendment 
(Combatting Misinformation and Disinformation) Bill 2023 (Disinformation 
bill). 


In its report on digital platforms’ disinformation measures discussed in 
Chapter 3, the ACMA noted that while steps being taken under the voluntary 
Australian Code of Practice on Disinformation and Misinformation (DIGI code) were 
good first steps, the ACMA recommended it have ‘a graduated set of new 
powers to combat misinformation and disinformation across the sector’ which 
would ‘increase transparency and ensure that digital platform services are held 
to account if voluntary industry efforts prove to be inadequate’.” 


In response to that report, the proposed powers in the Disinformation bill have 
been crafted to: 


° Enable the ACMA to gather information from platforms and require digital 
platform providers to keep certain records about matters regarding mis and 
disinformation. 

¢ Enable the ACMA to request industry develop a code of practice covering 
measures to combat mis and disinformation on digital platforms, which the 
ACMA could register and enforce. 

e Allow the ACMA to create and enforce an industry standard (a stronger 
form of regulation), should a code of practice be deemed ineffective in 
combatting mis and disinformation on digital platforms.” 


2 Ms Elaine Pearson, Asia Director, Human Rights Watch, Committee Hansard, 21 April 2023, p. 6. 


21 Ms Mia Garlick, Regional Director of Policy, Meta, Committee Hansard, 11 July 2023, p. 2. 


2 Department of Infrastructure, Transport, Regional Development, Communications and the Arts 
(Department of Communications), Communications Legislation Amendment (Combatting 
Misinformation and Disinformation) Bill 2023 — Fact sheet, June 2023, p. 3. 


23 


Department of Communications, Communications Legislation Amendment (Combatting Misinformation 


and Disinformation) Bill 2023 —Fact sheet, p. 1. 


75 


5.33 


5.34 


5.35 


5.36 


5.37 


Digital Industry Group Inc. (DIGI), the industry body responsible for the current 
DIGI code, has expressed in principle support for the proposed powers outlined 
in the ACMA’s report.” 


The Department of Communications outlined that the intent of the 
Disinformation bill is to: 
...tackle content that is reasonably likely to cause or contribute to serious 
harm. That, in a sense, is the intent of the bill: in a sense, for digital platforms 
to take steps and responsibility for the content on those platforms and, in 
doing so, take steps to address content that they judge could be likely to 


cause serious harm. So the focus is on the harm and the content rather than 
the intent or the source of the content, if that makes sense.” 


The Disinformation bill defines misinformation and disinformation as follows: 


e Misinformation is online content that is false, misleading or deceptive, that 
is shared or created without an intent to deceive but can cause and 
contribute to serious harm. 

e Disinformation is misinformation that is intentionally disseminated with the 
intent to deceive or cause serious harm. 

e Serious harm is harm that affects a significant portion of the Australian 
population, economy or environment, or undermines the integrity of an 
Australian democratic process.” 


ASPI did not agree that the above definitions were clear enough, ‘so it leaves 
subjectivity to the social media providers to decide what the litmus is for content 
that should be taken down’.”” 


Meta described the current model of the voluntary DIGI code as ‘a good way to 
both address the concerns of policymakers and communities about the 
transparency of the approach that we take to combatting misinformation and 
foreign interference, while also balancing the very important imperative of 
protecting free expression and making sure we're not overly censoring people 
online’. Meta further argued that the draft legislation goes further than just 
enforcing the DIGI code, and Meta warned that it saw ‘some potential for that 


2% Digital Industry Group Inc, ‘DIGI Welcomes The Government Providing ACMA With Oversight 
Powers Over Misinformation’, Media release, 20 January 2023. 


23 Mr Richard Windeyer, Deputy Secretary, Communications and Media Group, Department of 
Communications, Committee Hansard, 12 July 2023, p. 25. 


26 Department of Communications, Communications Legislation Amendment (Combatting Misinformation 
and Disinformation) Bill 2023 —Fact sheet, p. 1. 


27 


Ms Emily Mosely, International Cyber Policy Centre Coordinator, Australian Strategic Policy 


Institute, Committee Hansard, 20 April 2023, p. 21. 


76 


5.38 


5.39 


5.40 


5.41 


power to be abused or for it to be used in a way inadvertently chills free and 
legitimate political expression online’.”8 


The Department of Communications disagreed with the premise that the 
Disinformation bill may have an unintended consequence of censorship or 
chilling of online discourse, however it did concede that overall effect of the 
draft bill would censor people who shared content that was unintentionally 
false, but only where that content causes serious harm.” 


Google and YouTube stated it was still working on reaching a formal position 
on the bill, but expressed initial support for the proposals, including giving the 
ACMA the powers to enforce the DIGI code. Google reminded the committee 
that it was one of the first signatories to the DIGI code, and wanted more 
companies to sign up to increase its coverage.* 


In media reports, Victorian barrister Peter Clarke described the Disinformation 
bill as a ‘dangerous piece of legislation’ and noted that the definition of what 
constitutes harm were ‘so vague as to be dangerous’. Similarly, Sydney barrister 
Jeffrey Phillips SC said the bill ‘poses the ability to censor and shuts down 
debate’ and was a ‘bad direction for us to be going in’.*! 


The Department of Communications is undertaking a consultation on the 
exposure draft, seeking submissions by 6 August 2023, which will inform any 
changes to the draft bill.* 


Legal remedies 


5.42 


In addition to the sector-wide approach of regulating platforms to ensure they 
are compliant with meeting responsibilities to reduce CIB, the committee heard 
that more could be done to improve the legal frameworks for reporting and 
charging people over instances of suspected foreign interference. 


Improved reporting 


5.43 


The Australian Federal Police (AFP) stressed that reporting instances of 
suspected foreign interference is the first line of defence: 


28 Mr Josh Machin, Head of Public Policy, Australia, Meta, Committee Hansard, 11 July 2023, pp. 5-6. 


29 


Mr Richard Windeyer, Department of Communications, Committee Hansard, 12 July 2023, p. 25. 


3 Ms Rachel Lord, Senior Manager, Government Affairs and Public Policy, YouTube, Google, 
Committee Hansard, 11 July 2023, p. 37. 


3t Rhiannon Down and Sarah Ison, "Dangerous and Orwellian”: Tech giants and lawyers warn on 
Labor misinformation bill’, The Australian, 11 July 2023. 


32 Department of Communications, New ACMA powers to combat misinformation and disinformation, 
www. infrastructure.gov.au/have-your-say/new-acma-powers-combat-misinformation-and- 


disinformation (accessed 17 July 2023). 


77 


5.44 


5.45 


5.46 


5.47 


33 


Senator, my personal view is that the best strategy to defend against foreign 
interference is through high community and agency awareness and also 
knowledge of how to report it. If it's reported, we're able to understand it. 
And once we're able to understand it, we can work to disrupt and look at 
vulnerabilities that need to be corrected not only on individual case basis, 
but at more system level.* 


The AFP advised that foreign interference allegations ‘come to us through a 
number of means ... through Crime Stoppers, through direct reports to the AFP, 
referred from other departments, as well as through the National Security 
Hotline, as well as other government departments’.** ASIO likewise submitted 
that it has a number of channels for the reporting of concerns about being 
contacted for the purpose of foreign interference for clearance holders, members 
of the public, government organisations, and private sector companies. 


Home Affairs likewise stressed the importance of people reporting instances of 
foreign interference through the National Security Hotline and noted that ‘there 
are certainly times when there is an increase in certain communities reporting 
suspected foreign interference or interference, and we work very closely with 
those communities and will step up engagement with those communities to 
respond to that when we see those occurring’. 


Mrs Kateryna Argyrou of the Australian Federation of Ukrainian Organisations 
told the committee that her organisation made sure to report all instances of 
harassment and interference: 

Every time we've had a community member who has been harassed online 

or threatened — and we've had many community members who've received 


death threats through Telegram channels, through Facebook Messenger and 
through other social media — we've reported that [to the] the police.'%” 


Mr Peter Murphy of Australian Supporters of Democracy in Iran noted the 
challenges faced by people in reporting foreign interference but that once 
reported, it appeared to be taken seriously: 


It was a bit of a merry-go-round. We'd ring the Federal Police, and they'd 
say go to the New South Wales police. We'd ring the New South Wales 
police, and they'd say go to the Federal Police, so eventually I had to go in 
person to the Federal Police during the pandemic because nobody would 
really talk on the phone. But I think it was a reasonable exchange. I was 


Mr Stephen Nutt, Commander, Special Investigations, Counter Terrorism and Special 


Investigations Command, Australian Federal Police, Committee Hansard, 12 July 2023, p. 22. 


34 Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 23. 


35 


Australian Security Intelligence Organisation, Submission 2, p. 6. 


36 Ms Sally Pfeiffer, Acting First Assistant Secretary, Counter Foreign Interference, Department of 
Home Affairs, Committee Hansard, 12 July 2023, p. 8. 


37 Mrs Kateryna Argyrou, Co-Chair, Australian Federation of Ukrainian Organisations, Committee 
Hansard, 21 April 2023, p. 28. 


78 


5.48 


5.49 


5.50 


5.51 


interrogated or questioned and was able to convey all the information I 
wanted to give, and it was taken seriously ... I’m more confident that our 
agencies are getting a clearer view of what is going on and are more willing 
to take action to protect people here than they might have been before.* 


However, Human Rights Watch raised concerns that members of diaspora 
communities in Australia who may be subjected to threats and intimidation 
‘don't know what to do about those threats or who to report them to’ and 
recommended an information campaign to advise diaspora communities in 
Australia, including in other languages, not just English. 


The AFP noted that due to the sensitivities of the reported issues, people 
reporting via the National Security Hotline were generally not kept informed of 
progress on the matter they reported, and sometimes were not even 
acknowledged that a report had been made. However, the AFP did stress the 
continued importance of making such reports, particularly because reports are 
then sent to ‘multiple agencies and agencies that need to know’. 


The AFP went on to advise that: 


In terms of our response, we look at matters on a harm basis. So a high-harm 
report is something that is prioritised now. High harm in terms of 
community interference, or foreign interference in community, or 
transnational repression—it depends on which stream you're listening to— 
is really where there are actual threats or demands with menace that involve 
the potential for serious physical harm being directed at a person or a 
community. Those are the priority areas that we look at.” 


The AFP further advised that ‘The biggest challenge, as I pointed out earlier, is 
that foreign principal element. I know that there is a quantum of reporting 
where people are feeling intimidated or feeling that they're subject to foreign 
interference. In our case, if we are unable to establish a foreign actor 
involvement, that does limit our ability to respond under the foreign 
interference legislation’ .“! 


Charges and prosecution 


5.52 


Despite the prevalence of social media-based foreign interference, harassment 
and threats being experienced by diaspora communities in Australia— many of 
whom are Australian citizens—the AFP advised the committee there had been 
no instances where a person was charged under the National Security Legislation 


38 Mr Peter Murphy, Co-Secretary, Australian Supporters of Democracy in Iran, Committee Hansard, 


21 April 2023, p. 21. 


3 Ms Elaine Pearson, Human Rights Watch, Committee Hansard, 21 April 2023, pp. 4-5. 


4 Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 18. 


41 Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 18. 


79 


Amendment (Espionage and Foreign Interference) Act 2018 (Espionage Act) with 
foreign interference via a social media platform.” 


5.53 The AFP advised the committee of the range of elements that must exist in order 


for foreign interference to meet the threshold for offences under the 
Espionage Act: 


. our primary consideration is the involvement of a foreign actor and 
whether an individual is working in collaboration with a foreign actor or as 
a proxy. That's a key requirement. And then obviously we have to look at 
the other elements of the offence, whether it goes to government processes, 
political processes, political rights or democratic rights being exercised, and 
whether an intelligence objective of the foreign principal is what the activity 
is related to or it's adverse against the national security of Australia. We then 
consider whether the conduct involved an element of covert and deception 
or whether there was a threat of serious harm or the demand with menace. 
That's the collective of what needs to be proven.* 


5.54 The AFP did note that where an action might not meet the threshold of the 


Espionage Act—which requires either a foreign principal or a proxy of a foreign 
principal to be undertaking the action—the action may still be a crime under 
other laws: 


There also may be other criminal investigations, because conducting a threat 
or harassment or menace online is a separate offence, not under the foreign 
interference legislation...And of course if the posting is potentially hate 
crime related, this is not a Commonwealth jurisdiction; it's something that 
will fall to state and territory police.“ 


5.55 The AFP stressed that ‘no report is lost’ and outlined that where there are 


individuals who are criminally targeting the community, the AFP does prioritise 
those reports. Where it does not fall within its jurisdiction, they refer to state and 
territory police and advised the committee that “we don't just not respond’. 


5.56 ASIO also noted a range of activities it can undertake where charges cannot be 


42 


43 


44 


45 


laid: 


There are other things we do in the course of our engagement. We can 
engage with victims as well as perpetrators of foreign interference or people 
that we believe are likely to be involved in perpetrating foreign interference. 
That can have an effect of adding resilience, rendering the environment less 
permissive, if you like. I wouldn't go into the nature of those engagements. 
They're confidential by their nature. The point I'd leave you with is that the 
taskforce has a range of options at its disposal to seek to disrupt and reduce 


Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 16. 
Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 17. 
Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 23. 


Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 24. 


80 


the harm from foreign interference, including what we call community 
interference or transnational repression. 


5.57 The Law Council of Australia noted that widespread use of the foreign 


interference offences under the Espionage Act and the Criminal Code Act 1995 
(Criminal Code) was unlikely ‘given the challenges that exist in relation to 
successfully investigating and prosecuting persons who commit this offence 
when the "conduct" occurs outside Australia’. Nevertheless, the Law Council of 
Australia suggested that these measures could still prove useful in conjunction 
with other approaches.” 


5.58 This was supported by evidence from witnesses such as Mrs Kateryna Argyrou 


from the Australian Federation of Ukrainian Organisations, who told the 
committee: 


Last time I checked, we'd had over 40 official complaints registered with 
police, with registered numbers. We continue to add to that list. The 
Australian law enforcement agencies have been very open and willing to 
listen, but I think there is an issue here between where they can use the full 
force of the law and where they can just sympathise and say, 'We hear you, 
but there is really nothing we can do' ... So this is where we would hope that 
you [this inquiry] can hear our concerns on that point of view, and 
something can be discussed or done on that front. 


5.59 A joint submission from technical specialist University centres suggested that 


46 


47 


48 


49 


changes to relevant laws would be necessary to enable the use of technical 
methods and tools relating to the monitoring or investigation of foreign 
interference through social media and their results in judicial proceedings, 
writing: 


Litigation is a potential, but currently inadequate, antidote to 
disinformation. Litigation removes individuals from their informational 
bubbles or echo chambers, assign neutral judges or regulators - instead of 
simply the marketplace of ideas - to render a judgment on the truth or falsity 
of certain beliefs and compel action by responsible parties. However, 
litigation has not yet delivered on its potential. For example, criminal 
prosecution of offenses of foreign interference through social media, while 
theoretically possible, is often dismissed as practically infeasible given the 
jurisdictional and evidentiary challenges.” 


Mr Mike Noyes, Deputy Director-General, Intelligence Service Delivery, Australian Security 
Intelligence Organisation, Committee Hansard, 12 July 2023, p. 10. 


Law Council of Australia, Submission 27, pp. 2-3. 


Mrs Kateryna Argyrou, Australian Federation of Ukrainian Organisations, Committee Hansard, 
21 April 2023, p. 28. 


Joint University Submission, Submission 19, pp. 6-7. 


Countermeasures 


5.60 The committee heard that in addition to the significant gaps in identifying and 


reporting foreign interference, there are gaps in Australian Government 


countermeasures once foreign interference is detected. 


5.61 Overall, the committee heard the government should operate with greater 
transparency, including by being less reticent to ‘call out’ instances of foreign 


interference and providing advice on security concerns, and 


countermeasure operations should be conducted under a more rigorous 
framework, such as those being used in the European Union (EU) and 


United States (US). 


5.62 Dr Andrew Dowes, Director of RAND Australia advised that governments 


should be taking an analytical approach to developing countermeasures: 


It may be instructive to consider how an actor, whether it be foreign or 
domestic, might go about undertaking a disinformation campaign in order 
to understand how then that influence could be countered at each step of 
the disinformation process. In my view these problems of disinformation 
and information are not able to be defeated by a single action, but require a 
series of interventions, ranging from addressing the motivation of actors to 
addressing structural issues in social media networks, to various ways of 
reducing the likelihood of the audience believing or amplifying force 
content. In my view such interventions should be priorities for our 
government, as otherwise the risks and potential consequences of 
interference through social media will just continue to get worse. 


Transparent government communication 


5.63 The AHRC argued that any taskforce addressing foreign interference should, 


where possible, report more publicly than is currently done ‘to bring greater 


transparency to the ways in which misinformation and disinformation are being 
addressed both to enhance the public understanding of the risks to Australia, 


and ensure that other rights and freedoms are not disproportionately 


impacted’.®! 


5.64 ASPI noted the success experienced by other governments being more willing 


to call-out interference operations: 


So the question [is]...how do we shift the adversary's thinking about 
conducting these operations? For state actors, it might be about imposing 
diplomatic costs or pointing out that they are doing that and imposing a 
solution of just calling them out and sort of naming and shaming them. I 
think, at the international level, through multilateral agreements, there is a 
lot of scope for governments to make those public attributions. That does 


5% Dr Andrew Dowse, Director, RAND Australia, Committee Hansard, 20 April 2023, p. 27. 


5 Australian Human Rights Commission, Submission 9, p. 8. 


82 


5.65 


5.66 


5.67 


two things: it does deterrence but it does educate the public as well...Calling 
them out does really impose costs, and I think it is an easy win, really. 


Ms Elaine Pearson, Asia Director, Human Rights Watch advised that: 


...there is also a really important role that the Australian government can 
play in ensuring that the acts of intimidation, harassment and censorship 
that occur on apps like WeChat are publicised. Chinese-language 
communities in Australia need to be aware of that, and it shouldn't just be 
up to civil society organisations or think tanks, really, to be disclosing these 
incidents.*> 


Dr William Stolz also argued that in addition to reacting to single instances of 
foreign interference, ‘we need to be engaging in our own information operations 
to push our own positive narratives— again accepting that effectiveness is going 
to be ambiguous, but it is perhaps better to be proactive in pushing our own 
narratives into what is a maelstrom information environment and hope that we 
achieve a positive impact’ .™ 


Professor Rory Cormac agreed and noted that this type of response should not 
be restricted to ‘setpiece events like elections or regime change’ but should 
‘counter that daily drip of disinformation, interference and subversion on an 
intangible level, which just seeks to sow confusion and discord, exploit 
pre-existing schisms in society, and gradually chip away at trust in institutions 
like democracy’. Professor Corman further noted the recent countermeasures 
taken by the UK’s National Cyber Force as showing ‘nuance, maturity and 
evolution’ .* 


Advising on security concerns 


5.68 


5.69 


As discussed in earlier chapters, TikTok was banned from being installed on 
Australian Government-issued devices. A gap was discussed in relation to 
organisations providing contracted services to government. 


The Attorney-General's Department advised that the Protective Security Policy 
Framework (PSPF) ‘requires non-corporate Commonwealth entities to be 
accountable for security risks arising from any contractual arrangements they 
have and to then place security requirements on those they contract’. This was 
explained to mean that any entity with obligations under the PSPF must ensure 


52 Mr Albert Zhang, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 25. 


53 Ms Elaine Pearson, Human Rights Watch, Committee Hansard, 21 April 2023, p. 3. 


5 Dr William Stoltz, Private capacity, Committee Hansard, 20 April 2023, p. 38. 


5 Professor Rory Cormac, Director, Centre for the Study of Subversion, Unconventional Interventions 
and Terrorism, University of Nottingham, Committee Hansard, 20 April 2023, p. 39. 


83 


5.70 


that external contractors who work with sensitive government information 
must also adhere to the same risk approach to applications such as TikTok.* 


However, the Attorney-General's Department did concede that level of granular 
detail was not expected to be reported by departments in their annual reporting 
on their compliance with the PSPF, so whether or not departments had turned 
their minds to applying the ban to government contractors would not be 
known.” 


Regulated frameworks 


5.71 


5.72 


5.73 


Chapter 3 on international issues provided an extensive outline of the foreign 
interference approaches being used in the EU and US, such as the 
Disinformation Analysis and Risk Management (DISARM) open-source 
framework for analysis of interference instances and its ‘kill-chain’ approach to 
countermeasures. 


RAND Australia submitted that because a disinformation campaign involves a 
sequence of steps ‘for false information to be created, disseminated, observed 
and amplified’, that creates opportunities for countermeasures at each step, only 
one of which needs to be successful to knock out the whole chain. 


Countering efforts at each of these steps may help mitigate the impact of 
disinformation, including the use of information by actors that represents 
foreign interference. A strong countering strategy should combine such 
efforts within a survival chain, rather than expecting a singular solution to 
defeat disinformation.* 


Dr Andrew Dowse, Director of RAND Australia, expanded on this directly to 
the committee, citing the kill-chain philosophy being increasingly used in the 
EU as a tactic to address foreign interference: 


The steps to enabling a disinformation campaign go from the considering of 
the strategy and the message to setting up the means by which the message 
can be provided and transmitting the message. So there are steps. The 
countering of that is not necessarily sequential but can be concurrent. Some 
of the countering of those steps could be proactive. Some could be 
responsive. None of them are mutually exclusive, which is why I suggested 
you need lots of lines of effort. 


It's like a defence in depth, where some will get through the first step and 
some will get through the third but, through all those lines of effort, you 
should defeat a majority of those activities...this kill chain/survival chain 
concept has been applied in cybersecurity, very effectively, and I think it 


56 Ms Sarah Chidgey, Deputy Secretary, National Security and Criminal Justice, Attorney-General's 
Department, Committee Hansard, 12 July 2023, p. 20. 


5 Ms Sarah Chidgey, Attorney-General's Department, Committee Hansard, 12 July 2023, pp. 20-21. 


58 RAND Australia, Submission 11, p. 3. 


84 


lends itself very well to attempting to defeat disinformation campaigns as 
well.5? 


International cooperation 


5.74 


5.75 


Ms Lindsay Gorman of the Alliance for Securing Democracy advised that 
Australia: 
... join with democratic allies and partners to develop a comprehensive 
framework for addressing the threats posed by authoritarian internet apps 
and critical information infrastructure. Given Australia's strong work on 


foreign interference, it is naturally poised to take a leading role in these 
efforts. 


Meta similarly called for a global collaborative approach, noting that 
‘combatting foreign interference requires multisectoral, whole-of-society 
approaches towards building a strong security ecosystem not only within 
Australia but across the region and globally’. 


Cross-sector collaboration 


5.76 


5.77 


5.78 


The committee heard that greater collaboration between government, tech firms 
and civil society experts would not only improve coordination of overall 
countermeasures, but would help each sector in the specific areas they are 
responsible for. The areas of threat intelligence and technical research were 
particularly called out. 


Meta argued for ‘greater information sharing of IO threat signals among tech 
companies and between platforms, civil society and government, while 
protecting the privacy of innocent users who may be swept up in these 
campaigns’. 


Both ASIO and Home Affairs noted that they do not share intelligence on 
specific instances of suspected foreign interference. Home Affairs advised: 


We don't undertake referrals about specific pieces of information in relation 
to foreign interference. Our engagement with social media platforms is to 
the level of the broader understanding of misinformation and 
disinformation and how it could be used and the processes that the social 
media platforms might themselves look at with their terms of use and the 
referrals they receive regarding concerns.® 


5 Dr Andrew Dowse, RAND Australia, Committee Hansard, 20 April 2023, p. 29. 


60 Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 9. 


61 Ms Mia Garlick, Meta, Committee Hansard, 11 July 2023, p. 2. 


€ Meta, Submission 32, p. 17. 


& Ms Sally Pfeiffer, Department of Home Affairs, Committee Hansard, 12 July 2023, p. 12. 


85 


5.79 


5.80 


5.81 


5.82 


5.83 


ASIO advised that: 


One of the challenges we'd have there is that even in those circumstances 
where we can identify it, providing that intelligence to individuals or 
companies that don't employ individuals with clearances is a real challenge 
for us.“ 


Both Home Affairs and ASIO noted there was no policy reason they were aware 
of that would preclude social media employees from seeking security 
clearances, and Home Affairs advised it would then allow them to share some 
information. 


In regards to technical research, the issue of funding arose. Meta recommended 
there should be more support for private and public ‘innovation and 
collaboration on technical detection of adversarial threats such as manipulated 
media, including deepfakes’.® 


Dr Dowse of RAND Australia noted the limited funding avenues to undertake 
research on social media data. He advised that RAND Australia had to seek US 
funding to undertake research on Australian issues, and stated ‘I would dearly 
like to see the Australian government perhaps providing more sources of 
funding so we can do this research’. 


The following chapters, on platforms and civil society responsibilities, discusses 
the issue of technical research in greater detail. 


64 Mr Mike Noyes, Australian Security Intelligence Organisation, Committee Hansard, 12 July 2023, 
p. 12. 


6 Meta, Submission 32, p. 17. 


6° Dr Andrew Dowse, RAND Australia, Committee Hansard, 20 April 2023, p. 28. 


6.1 


6.2 


6.3 


Chapter 6 
Platforms 


Current practice and identified gaps 


The introductory chapters to this report outlined the important and central role 
that social media plays in the lives of many Australians, and that depending on 
how it is used, social media can either strengthen or undermine democracy. 
Further, it was noted that because of its depth and reach into nearly every single 
person's life, social media is being increasingly used as a vector for foreign 
interference. 


While some technology firms are taking some steps towards addressing the 
issue of foreign interference on their social media platforms, this chapter 
outlines the overwhelming evidence that nowhere near enough is being done. 


An additional specific area of risk is social media platforms which originate 
from authoritarian states. These issues are discussed separately, in 
acknowledgement of the particular risks posed. 


Platform responsibilities 


6.4 


6.5 


xt 


2 


Social media companies have responsibilities for content published on their 
platforms. With regard to foreign interference, the Australian Code of Practice on 
Misinformation and Disinformation (DIGI Code), while voluntary, does require 
platforms to ‘address concerns regarding disinformation and credibility 
signalling for news content'.! 


The Australian Communications and Media Authority (ACMA) noted that the 
DIGI Code only has eight signatories. The ACMA stated there are a number of 
platforms operating in Australia which chose not to become part of the code, 
and the ACMA is aware of the ‘extent to which there might be misinformation 
and disinformation which has the risk of contributing to serious harm’. 
The ACMA stated it had engaged with a number of those platforms over the 
years and encouraged them to join the code. The ACMA further noted that 
Digital Industry Group Inc. (DIGI) had updated the code's reporting 


Digital Industry Group Inc (DIGI), Australian Code of Practice on Misinformation and Disinformation, 
Updated 22 December 2022, p. 2. 


Signatories include: Adobe, Apple, Google, Meta, Microsoft, Redbubble, TikTok and Twitter. 


87 


88 


6.6 


requirements to reduce the reporting burden for, digital platforms, so it hoped 
that might result in some platforms electing to sign up to the DIGI Code.’ 


The ACMA noted that it would be looking at information reporting 
requirements under a similar code operating in Europe, to compare and contrast 
with what platforms are reporting in Australia.+ 


Platform actions to address interference 


6.7 


Meta 
6.8 


6.9 


Platforms provided details to the inquiry on actions they take to address foreign 
interference. Platforms noted their actions are targeted to address any instances 
of coordinated inauthentic behaviour (CIB), regardless of whether it is for the 
purpose of foreign interference or is undertaken by non-state actors 
(often financially motivated). 


actions 

In its submission, Meta (which owns Facebook, Instagram, WhatsApp and the 
newly launched Threads) outlined for the committee the three main strategies it 
uses to combat foreign interference via its platforms, which include: 


* automated defences that leverage machine learning to detect and block bad 
actors: such as systems that find and block millions of fake accounts every 
day, most within minutes of creation; 

e threat intelligence analysts who hunt for and disrupt CIB not caught by the 
automated defences; and 

e collaboration by sharing information with counterparts in industry and with 
government, civil society and the media.’ 


The Department of Home Affairs (Home Affairs) noted the work undertaken by 
Meta, submitting that between 2017 and 2022 'Meta disabled and publicly 
reported on over 200 covert influence operations that violated its policies' and 
that these operations ‘originated from over 60 countries and targeted both 
foreign nations and their own domestic public debate'’.¢ 


Twitter actions 


6.10 


3 Ms 


4 Ms 


5 Ms 


Mr Nick Pickles, Head of Global Government Affairs, Twitter, told the 
committee that Twitter has an approach of early intervention when it suspects 
foreign interference or CIB, and due to the difficulties in definitively attributing 
content Twitter doesn't necessarily wait for this before taking action: 


Cathy Rainsford, General Manager, Content and Consumer Division, Australian 


Communications and Media Authority, Committee Hansard, 12 July 2023, pp. 28-29. 


Nerida O'Loughlin, Chair, Australian Communications and Media Authority, 


Committee Hansard, 12 July 2023, p. 29. 


Mia Garlick, Regional Director of Policy, Meta, Committee Hansard, 11 July 2023, p. 2. 


6 Department of Home Affairs, Submission 1, p. 3. 


89 


Often we're looking at behaviour signals. They may be linked to accounts, 
networks or origin. Obviously many of these actors are trying to hide and 
obfuscate where they are, so it's not as simple as saying, 'Show me all the 
Twitter accounts from one country.’ We look at content. 


6.11 Mr Pickles then cited initiatives such as Community Notes, verification and 
Twitter Blue as additional programs designed to capture CIB. Community 
Notes was explained as allowing people on Twitter to add context to other 
people's tweets: 

Those tweets can be added to any account, including advertisers, political 
leaders and prominent influencers. By looking at the people who are adding 
that data, we're already seeing a significant impact, with an up to 35 per cent 
reduction in the sharing of those accounts based on context added by other 
users.’ 


LinkedIn 

6.12 LinkedIn presents a different risk for foreign interference than other social 
media platforms, as it is a professional networking site. In February 2023, the 
Australian Security Intelligence Organisation (ASIO) head Mr Mike Burgess 
noted that ASIO identified nearly 16 000 Australians publicly declaring on 
professional networking sites they have a security clearance, and 1 000 more 
revealing they worked in the intelligence community. Mr Burgess said 'these 


people may as well add "high-value target" to their profiles.* 


6.13 In recent years, LinkedIn has become heavily abused by threat actors seeking to 
distribute malware, perform cyberespionage, steal credentials, or conduct 
financial fraud. In 2022, LinkedIn was used by Lazarus North Korean hacking 
group for cybercriminal and espionage operations, contacting victims via 
targeted private messages on the platform.’ 


6.14 LinkedIn noted that the largest threat is posed by fake accounts and reported 
that in 2022 it 'blocked more than 80 million fake accounts worldwide, of which 
about 400 000 were attributed to Australia’. 


Google and YouTube 

6.15 Google and YouTube provided information to the committee on steps it takes to 
address foreign interference on its platforms, via the Threat Analysis Group 
(TAG), a'global team of analysts and security experts that analyses and counters 


7 Mr Nick Pickles, Head, Global Government Affairs, Twitter, Committee Hansard, 11 July 2023, pp. 42 
and 43. 


8 Casey Tonkin, 'Don't put your security clearance on LinkedIn’, InformationAge, 23 February 2023. 


? Veronica Chierzi and Mayra Rosario Fuentes, 'A Growing Goldmine: Your LinkedIn Data Abused 
For Cybercrime’, TrendMicro Business, 28 March 2023. 


10 Mr Joshua Reiten, Senior Director, Legal— Digital Safety, LinkedIn, Committee Hansard, 11 July 2023, 
p. 16. 


90 


6.16 


serious threats to Google and our users, including threats from government 
backed attackers, serious cybercriminals and information operations'."! 


In relation to countermeasures taken by YouTube, the committee was told: 


We particularly focus on disrupting coordinated influence operations on 
YouTube. For example, in the first quarter in 2023 we terminated more than 
900 YouTube channels linked to Russia and more than 18,000 linked to 
China, as part of our investigations into coordinated influence operations. 
These actions are in addition to YouTube's ongoing enforcement of 
community guidelines, which resulted in the removal of more than 
5.6 million videos globally in the fourth quarter of 2022." 


6.17 However, YouTube did acknowledge that even in the recent past (2021) it had 


not always responded to remove harmful content as fast as it should have." 


WeChat 


6.18 


6.19 


6.20 


WeChat made a submission to the inquiry, as it did to the similar inquiry of the 
46th Parliament, however that submission contained no specific information on 
how it addresses disinformation, surveillance, censorship, disinformation or 
CIB on its platform. Notably, WeChat repeatedly declined multiple invitations 
to participate in a public hearing to answer direct questions from the committee, 
ignoring that the invitation allowed them to participate via videoconference 
from any location in the world as other witnesses utilised." 


On 4 July 2023, as Chair of the Select Committee, Senator James Paterson sent 
an open letter to WeChat urging them to reconsider their refusal to appear in a 
public hearing. On 10 July 2023, WeChat responded to Senator Paterson to 
reiterate their stated intention of 'working collaboratively with Australian 
regulators and authorities’ and said that it remained ‘committed to providing 
responsive information to the committee in writing’ but continued to refuse to 
front up in an open forum.’ 


In doing so, WeChat has demonstrated contempt for the Australian Parliament 
and has shown the Australian public that WeChat, and their parent company 
Tencent, is not genuinely committed to being held accountable for the serious 
allegations of censorship, surveillance and foreign interference at the hands of 


Mr Shane Huntley, Senior Director and Global Lead, Google Threat Analysis Group, Google, 
Committee Hansard, 11 July 2023, p. 35. 


2 Mr Shane Huntley, Google, Committee Hansard, 11 July 2023, p. 35. 


Ms Rachel Lord, Senior Manager, Government Affairs and Public Policy, YouTube, Google, 
Committee Hansard, 11 July 2023, p. 36. 


4 WeChat, Submission 15, pp. 3-4. 
5 Senator James Paterson, 11 July 2023, available at https://twitter.com/SenPaterson/status/ 


1678557229883207681 (accessed 26 July 2023). 


91 


6.21 


6.22 


6.23 


6.24 


6.25 


6.26 


6.27 


the Chinese Communist Party (CCP) which is rife on its platform and is a real 
concern to WeChat users in Australia. 


Senator Paterson, on behalf of the committee, submitted 53 detailed questions 
to WeChat asking for an explanation on its links to the CCP, whether it censors 
content critical of the Chinese Government and promotes CCP propaganda, and 
whether the application is used to surveil and target Australian users critical of 
the regime, including its human rights record. 


WeChat was initially required to respond by 21 July 2023, however WeChat 
requested via the secretariat an extension of time and was given until 
26 July 2023 to provide answers to these 53 questions. 


WeChat submitted its response to these 53 questions on 26 July 2023, however 
unfortunately WeChat failed to meet the transparency test by not providing 
direct answers to the questions that were asked of them. 


WeChat flatly denies censorship, surveillance and control is being exercised on 
the platform even though this has been repeatedly and convincingly 
demonstrated by independent researchers and experts, including those who 
testified before the committee. 


In relation to censorship on the platform, Dr Seth Kaplan testified that WeChat 
is: 


... doing the censoring for the party, and there are what you might call 
united front and other agents whose content, basically, is being promoted 
... There is extensive censorship, there is extensive demoting, people are 
being banned and people are being suspended ... I wouldn't say that the 
CCP is directly doing it. I think Tencent is under instructions on how it must 
manage the platform." 


In relation to surveillance and control on WeChat, Dr Kaplan added: 


... you have to understand that this surveillance and control of the [Chinese] 
diaspora operates on two levels. One is WeChat, and then there are 
individuals. They could be United Front; they could be other actors. ..or they 
may be just rabid nationalists ... The non-WeChat avenues for monitoring, 
constraining and controlling this vulnerable population would be much less 
effective if there were no WeChat.!” 


On WeChat's links to the CCP, CyberCX submitted that the ‘risk that the 
dominant position of social media platforms is abused by malign actors is 
heightened for platforms, such as TikTok and WeChat, which are linked to 
authoritarian governments’. Internet 2.0 argued in their submission that 'we 
consider that WeChat is under structural pressure to support the CCP's rule of 


16 Dr Seth Kaplan, Private capacity, Committee Hansard, 20 April 2023, p. 13. 


17 Dr Seth Kaplan, Committee Hansard, 20 April 2023, p. 16. 


92 


6.28 


6.29 


law. We believe this structural market pressure may come at a disadvantage to 
all other governments’ rule of law'.'8 


The Australian Strategic Policy Institute's (ASPI) 2020 report into TikTok and 
WeChat found that WeChat has 'become the long arm of the Chinese regime, 
extending the PRC's [People's Republic of China's] techno-authoritarian reach 
into the lives of its citizens and non-citizens in the diaspora. WeChat users 
outside of China are increasingly finding themselves trapped in a mobile 
extension of the Great Firewall of China through which they're subjected to 
surveillance, censorship and propaganda’. 


WeChat's dismissive non-answers are a disingenuous effort to assist the 
committee by engaging in blatant spin and corporate talking points, and is 
further evidence for the contempt they have for the Australian Parliament. 


TikTok 


6.30 


6.31 


TikTok provided descriptions of actions it takes against CIB on its platform. 
TikTok's Community Guidelines ‘prohibit content that could mislead our 
community about civic processes or matters such as public health and safety’. 
TikTok submitted that its community guidelines which prohibit misleading 
information are enforced through safety professionals and moderators, 
technology-based flagging and via a fact checking partnership with 
Australian Associated Press.” 


TikTok reported that between July and September 2022, it blocked 41 459 159 
spam accounts, removed 94 733 447 videos posted by spam accounts and 
removed 759 044 040 fake followers. TikTok submitted that five networks of 
operations involved in spam account activity, fake engagement and covert 
influence operations on-platform were removed in the same period.” However, 
the committee notes this appears to be the global number of removed networks, 
which may be considered very low when compared against reports of the 
prevalence of disinformation influence operations. 


Ongoing concerns 


6.32 


The rest of this chapter outlines concerns raised around the success of current 
actions in addressing foreign interference and CIB, as well as the complete 
absence of action in some cases. 


18 Internet 2.0, Submission 17 Attachment 1, pp. 4-5. 


Fergus Ryan, Audrey Fritz, Daria Impiombato, "TikTok and WeChat: Curating and controlling 


global information flows’, Australian Strategic Policy Institute, 8 September 2020. 


2 TikTok, Submission 30, pp. 4-5. 


21 TikTok, Submission 30, p. 9. 


93 


Content moderation 


6.33 


6.34 


6.35 


6.36 


The committee heard that content moderation is a concern to many 
stakeholders, who were thought that either platforms were not removing 
malignant content fast enough, or that platforms were engaging in censorship 
by removing content that should remain, either because of inappropriate 
requests from governments of or due to problems with fact-checking processes. 


The Australian Human Rights Commission (AHRC) noted that platforms use a 
mix of automated technology and human moderators to address 
disinformation, and it did not think that current efforts were adequate under the 
growing volumes of disinformation.” 


Home Affairs noted a study which found weaknesses in TikTok and Meta 
moderation of advertisements as part of a controlled experiment: 
TikTok failed to catch 90 per cent of ads featuring false and misleading 
messages about elections in the United States, while Meta was only 
'... partially effective in detecting and removing the problematic election 
ads' as part of the experiment. Similar studies conducted globally, indicate 
social media platform content moderation success can vary from one 
country to another.” 


ASIO submitted that it would support measures requiring platforms and service 
providers to dedicate specific resources to the identification and moderation of 
disinformation content, published on their services 'commensurate with the 
volume of content and reach of their services’. 


Reporting content for removal 


6.37 


6.38 


The removal of content which breaches platform standards has two aspects. The 
first is whether or not platforms are responsive to legitimate reports from 
individuals, agencies or experts on foreign interference content, and the second 
aspect, discussed later in this section, is how platforms respond when they 
receive inappropriate requests for content removal. 


The committee heard from community members and expert organisations that 

reporting instances of foreign interference directly to platforms does not result 

in swift cooperation to take down content. Mrs Kateryna Argyrou, Co-Chair of 

the Australian Federation of Ukrainian Organisations told the committee that: 
On Facebook, where we can report certain posts, videos and content, we 


need to have hundreds, if not thousands, of our community members 
reporting it. Sometimes it gets taken down; in most cases it doesn't ... we 


22 Australian Human Rights Commission, Submission 9, p. 7. 


23 Department of Home Affairs, Submission 1, p. 3. 


24 


Australian Security Intelligence Organisation, Submission 2, p. 6. 


94 


6.39 


6.40 


6.41 


6.42 


6.43 


can report on YouTube taking action, but Facebook, which is a huge 
platform, to a large extent does absolutely nothing.” 


Conversely, Meta advised the committee that it takes an approach to 'make 
ourselves accessible and available to individuals and experts to come to us when 
they might be experiencing [harassment] is in addition to the broader systems 
that we have in place to detect this type of behaviour proactively and remove 
it.26 


Ms Vicky Xu, a journalist and policy analyst, noted that current processes to 
remove content take far too long, particularly when the content is directed at 
intimidating or attacking an individual: 


It took a couple of months for anything to actually happen and for YouTube 
to take action, and, by that time, hundreds of thousands of people had 
watched the content. I think there are things we can do to establish a kind of 
mechanism to—I can't speak more frankly than this—kill that content early 
and faster because that is very damaging. The same goes for platforms like 
Facebook and Twitter.’ 


Ms Xu noted the balancing act between taking action to protect individuals, 

versus protecting against undue censorship: 
How do we treat this? If the Chinese state makes a whole package of 
information in order to conduct character assassination against journalists 
who live in democracies, what is the difference between that and, for 
example, hate speech or violent content? I don't think that these two 
categories of harmful information are, by nature, very different. Currently, 
as I understand it, we don't have the mechanism or a way to get there fast 
and get rid of this content. I'm very aware that, by speaking like this, I'm 
encouraging censorship of a kind, but I guess this is a question I'm going to 
throw back to you: do we need more censorship around these things, or do 
people like me just drown in misinformation?” 


Twitter submitted that foreign interference should be approached ‘as a broad 
geopolitical challenge, not one of content moderation’, and argued that removal 
of content alone will not address this challenge.” 


Extra-territorial censorship through informal channels as foreign interference 
The committee heard that the system of reporting misinformation and 
disinformation for removal can itself be used as a tool of foreign interference or 
censorship and further, that some of those requests are made informally through 


2 Mrs Kateryna Argyrou, Co-Chair, Australian Federation of Ukrainian Organisations, 
Committee Hansard, 21 April 2023, p. 30. 


2% Mr Josh Machin, Head of Public Policy, Australia, Meta, Committee Hansard, 11 July 2023, p. 4. 


27 Ms Vicky Xu, Senior Fellow, Australian Strategic Policy Institute, Committee Hansard, 21 April 2023, 
p. 36. 


28 Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 36. 


2 Twitter, Submission 20: Foreign Interference through Social Media inquiry (46th Parliament), p. 2. 


95 


6.44 


6.45 


6.46 


6.47 


back channels by foreign governments and are not appropriately disclosed by 
social media platforms. This is of particular concern when requests are being 
made after pressure by authoritarian states, and the broader risks posed by those 
governments are discussed in detail later in this chapter. 


As ASIO pointed out to the committee, there are a range of activities which, 
when conducted openly, would not constitute foreign interference under 
Australian legislation, but 'could become foreign interference if they involve the 
hidden hand of a foreign state'.30 


The committee heard that extra-territorial censorship, such as blacklisting, 
visibility limiting or manipulation of visibility undertaken by social media, on 
request or under pressure from foreign governments, is an activity which can 
‘have a direct impact on the human rights of Australians or those living in 
Australia, as well as undermining Australia's democracy'.*! This is particularly 
the case when requests or demands by foreign governments for social media 
companies to remove or reduce visibility of content, or de-boost political figures 
are not disclosed to the public, and where the action taken by social media 
companies to censor or limit content impacts on the visibility of Australian users 
and free political discourse in Australia. 


As the AHRC submitted to the committee: ‘social media platforms, which 
function as a digital "town square" for free speech and self-expression, are 
increasingly affected by censorship. In particular, the expansion of the internet 
and social media has seen increased examples of extra-territorial censorship, 
where governments seek to suppress speech outside of their national borders’. 
"Badiucao, a notable artist who criticises the CCP, informed the committee that 
in some cases, the content reporting mechanisms were used by authoritarian 
states to censor dissidents: 

For example, on Twitter, they would report certain accounts without any 

basis. But that kind of campaign was forcing the algorithm from Twitter to 

respond to these reports and suspend the account targeted. This 


methodology has been very useful and commonly used by the Chinese 
government to silence critical voices outside of China.’ 


Human Rights Watch also pointed to whistleblower Peiter Zatko, Twitter's 
former chief security officer who claimed that the security shortcomings of 
Twitter constituted '[n]egligence and even complicity with respect to efforts by 
foreign governments to infiltrate, control, exploit, surveil and/or censor the 


30 Australian Security Intelligence Organisation, Submission 2, p. 4. 


31 Australian Human Rights Commission, Submission 9, p. 15. 


32 Australian Human Rights Commission, Submission 9, p. 15. 


3 Ms Vicky Xu, Australian Strategic Policy Institute, Committee Hansard, 21 April 2023, p. 36. 


96 


6.48 


6.49 


6.50 


6.51 


company's platform, staff, and operations'.** Human Rights Watch further 
noted: 
Before Musk's purchase of the platform, Twitter had quickly reacted to 
requests to protect the accounts of Chinese human rights defenders. After 
Musk's acquisition, the gutting of the infrastructure and staff that deal with 


these issues threatens to change that equation between the platform and 
China. 


The AHRC argued that 'transparency is the key to ensuring that censorship 
(including extra-territorial censorship) does not unduly restrict the exercise of 
free speech in Australia' and therefore recommended that 'government should 
mandate that all social media platforms publicly disclose, in detail, all the 
content they censor and make it an offence to censor content where that has not 
been publicly disclosed to users'.* 


Twitter acknowledged in evidence to this committee that that such pressure 
from foreign governments had regularly occurred and had not been historically 
disclosed to its users: 

Senator Chandler: What if it was an informal request [to take down or censor 


a tweet] from a government official? Would you let the user know who had 
made that request? 


Mr Pickles: Historically, no. But this is actually one of the areas where we 
are looking to make significant changes to guard against the kind of pressure 
that the Twitter files disclosed that we as a service face.37 


Both Meta and Twitter referred to their transparency measures in place to report 
occasions where content is removed or restricted based on a legal request from 
a government or regulator. Meta advised the committee that it makes 
‘information transparently available relating to requests that we receive from all 
government around the world for content restrictions or requests for user 
data’. 


Meanwhile, Twitter acknowledged that it may not be aware of all instances of 
requests to take down or censor content from officials acting on behalf of a 
foreign government: 

Senator Chandler: What if the request to take down or censor a tweet was 


made by a foreign government? Would you let the user know that it was a 
foreign government making the request? 


34 Human Rights Watch, Submission 12, p. 8. 


3 Human Rights Watch, Submission 12, pp. 7-8. 


36 Australian Human Rights Commission, Submission 9, p. 16. 


37 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 48. 


38 


Meta, answers to written question on notice 1-11 (received 19 July 2023), p. 1-2. 


97 


6.52 


6.53 


6.54 


6.55 


6.56 


Mr Pickles: If it came through a legal process, yes, we would. If it was 
someone in the Twitter app pressing a reporting button as a regular user, 
we might not know that person is from a foreign government. But in the case 
of a legal process — we receive thousands every year — we do communicate 
to the individual and actually provide them with a copy of the request as 
well. 


The Twitter files referred to in Mr Pickles' evidence to the committee widely 
documents recent revelations from Twitter itself that governments and 
government staff often make informal or semi-formal requests or demands to 
staff at social media companies that content be censored or removed: 

Slowly, over time, Twitter staff and executives began to find more and more 

uses for these tools. Outsiders began petitioning the company to manipulate 


speech as well: first a little, then more often, then constantly. By 2020, 
requests from connected actors to delete tweets were routine.“ 


Both Meta and Twitter were unable to provide country level data on 
government requests outside of formal legal requests to remove or moderate 
content. 


Meta did not directly address the question of whether it removes or restricts 
content for its users, including Australian users, following a request from a 
foreign government agency, regulator or official, where the content is not a 
breach of local law (emphasis added).“! 


Meta referred to its transparency report when asked whether Meta has ever 
acted on a request for content moderation on its platforms from the 
Russian Government, the Chinese Government or the Iranian Government or 
any persons connected to those regimes. However, those transparency reports 
only cite legal requests and not requests made through other informal 
channels.“ 


Additionally, Meta's transparency report does not include data on content that 
they removed for violating their policies following a request from a foreign 
government: "This report details instances where we restricted access to content 
based on local law. It does not include content that we removed for going 
against our policies’. 


39 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 48. 
4 Matt Taibbi, The Twitter Files, 13 April 2023, https://twitterfiles.substack.com/p/1-thread-the- 


twitter-files (accessed 27 July 2023). 


41 Meta, answers to written questions on notice 1-11 (received 19 July 2023), p. 1-2. 


Meta, answers to written question on notice 1-11 (received 19 July 2023), p. 2-3. 


43 Meta, Transparency Center: Content restrictions based on local law, https://transparency.fb.com/ 
data/content-restrictions/ (accessed 27 July 2023). 


98 


6.57 


6.58 


6.59 


6.60 


Twitter was unable to provide detailed information about 
Australian Government agencies making requests to remove, restrict or limit the 
visibility of content that were not from a regulator acting to address an alleged 
breach of law.“ 


While much of the public reporting on this issue focuses on pressure applied by 
United States (US) authorities to social media companies, companies 
acknowledge that similar requests outside of formal legal process are regularly 
made or attempted by foreign governments. When asked what processes are in 
place to ensure that Twitter's staff are not being target by foreign governments 
to action certain requests, Twitter told the committee: 


Obviously, there are a number of different ways that foreign governments 
may target us as a company: through our employees is one and through our 
infrastructure is another. We have a corporate security team working across 
all of those threat vectors to keep Kathleen, me and our colleagues safe.” 


Social media companies have extensive flexibility within the application of their 
content rules to determine when content will, or won't be removed. 
Meta's Community Standards provides: 


In some cases, we allow content — which would otherwise go against our 
standards — if it's newsworthy and in the public interest. We do this only 
after weighing the public interest value against the risk of harm, and we look 
to international human rights standards to make these judgments. In other 
cases, we may remove content that uses ambiguous or implicit language 
when additional context allows us to reasonably understand that the content 
goes against our standards.* 


Twitter acknowledged that pressure can be further amplified by overly broad 
and restrictive laws pressuring social media companies to remove or restrict 
content under poorly defined claims of 'misinformation’ or ‘social harm’: 


Globally, in pretty much every region and market we operate in, there is 
more regulation being proposed. In many countries, the legal definitions 
being proposed are so broad as to—I believe—pose a chilling risk to free 
expression. In some countries, it's phrases like ‘harmful content. 
Misinformation and disinformation are certainly concerns. We're seeing the 
pendulum swing towards more restrictive laws that don't necessarily have 
the same checks and balances or the ability to seek redress to the legal 
process that you would expect. Also, these decisions are being outsourced 
from governments to private companies to make the exact determination 
that you just talked about in terms of who decides whether content is illegal. 
Is it the state, or is it private companies? One trend we're definitely seeing is 
very broad laws being used to push that decision onto private companies 


44 Twitter, answers to written question on notice (received 25 July 2023), p. 1. 


45 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 49. 


46 Meta, Transparency Center: Facebook Community Standards, https://transparency.fb.com/en-gb/ 
policies/community-standards/ (accessed 27 July 2023). 


99 


under threat of significant financial and, in some cases, criminal penalties. 
All of that will have a chilling effect on free speech.” 


Fact checking 


6.61 


6.62 


6.63 


6.64 


6.65 


The committee explored the issue whereby identifying misinformation and 
disinformation relies somewhat on common agreement on what information is 
factual and/or truthful. The role of fact-checking entities is discussed in greater 
detail in the chapter on civil society. 


The Department of Infrastructure, Transport, Regional Development, 
Communications and the Arts (Department of Communications) advised that 
under the proposed changes in the exposure draft of the 
Communications Legislation Amendment (Combatting Misinformation and 
Disinformation) Bill 2023, ‘the judgement or the determination of 
disinformation and misinformation on a digital platform is a responsibility that 
is being quite intentionally left in the hands of the digital platforms to manage 
themselves'.‘8 


Meta disagreed with that principle, stating that 'US based multinational 
technology companies should not necessarily be deciding some of these matters' 
and outlined that it invested in independent fact checkers, published 
transparency reports and has fact checks published on the fact-checker websites, 
'so there can be debate around what content has been marked for removal or 
marked as false so that transparency can be applied across all of industry’. 


Meta advised that the three firms it engages as fact checkers includes 
Australian Associated Press (AAP), Agence France-Presse (AFP) and 
RMIT FactLab and noted that all of them ‘are accredited by the International 
Fact-Checking Network, which is the gold standard organisation of 
organisations that follow independent expert editorial approaches in the 
approach that they take to fact-checking'.” 


Meta explained that where the fact checking partner identifies false information, 
Meta does not remove the content but places a warning label over the content 
so people can click through and see the fact check statement. Meta noted that 
‘reasonable minds could disagree on what constitutes misinformation and we 
do not want to find ourselves in the position where we are making those 


47 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 51. 


48 Mr Richard Windeyer, Deputy Secretary, Communications and Media Group, Department of 


Infrastructure, Transport, Regional Development, Communications and the Arts (Department of 
Communications), Committee Hansard, 12 July 2023, p. 26. 


4 Ms Mia Garlick, Meta, Committee Hansard, 11 July 2023, pp. 6 and 14. 


100 


judgements, so that's an area where we do treat speech a little differently, 
depending on who the speaker is’. 


Job cuts 


6.66 


6.67 


6.68 


The Department of Communications noted that recent job cuts are an emerging 
concern for the ability of digital platforms to respond to and counter foreign 
interference. It further noted that the Australian Government expects digital 
platforms to still fulfil their commitments under the DIGI Code: 


Twitter, Meta, Google, TikTok, Snap, Microsoft and Amazon have all 
announced significant job cuts, with Apple pausing almost all new hiring. 
This raises questions about the impact of job cuts on Australian based staff, 
and moderation, safety, policy and government engagement teams globally. 
Media reporting indicates that these cuts have impacted moderation and 
safety teams at some platforms, e.g. job cuts at Twitter have affected about 
15 percent of its Trust and Safety Group globally and most of its Australian 
staff working on public policy and safety issues." 


Human Rights Watch submitted that in the past, Twitter had responded quickly 
to requests to protect the accounts of the Chinese human rights defenders, but 
stated there is a chance after the recent ownership changes that a reduction in 
staff numbers 'threatens to change that equation between the platform and 
China’. 


Twitter responded to these allegations directly to the committee, stating: 


Contrary to media reporting, when the restructuring was happening the 
trust and safety team was affected disproportionately less compared to other 
teams in the company. You'll have heard our new owner speaking about the 
importance of content moderation and the importance of preventing 
manipulation. Indeed, he's spoken about how one of the primary motivators 
for purchasing the company was preventing manipulation.” 


Transparency 


6.69 


6.70 


Transparency, or rather the lack of it, was raised consistently by many 
organisations and expert witnesses as an issue of key concern. Transparency 
issues were raised across many different domains, such as transparency in 
reporting content removal, recommender algorithms and actions taken against 
coordinated inauthentic behaviour. 


In relation to transparency through reporting, Meta submitted that it reports 
regularly on its approach to CIB through quarterly Community Standards 


5 Mr Josh Machin, Head of Public Policy, Australia, Meta, Committee Hansard, 11 July 2023, p. 11. 


51 Department of Communications, Submission 7, p. 3. 


52 Human Rights Watch, Submission 12, pp. 7-8. 


53 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 41. 


101 


6.71 


6.72 


6.73 


6.74 


6.75 


6.76 


Enforcement Reports, Monthly Adversarial Threat Reports, and via the Threat 
Report — State of Influence Operations 2017-2021. 


Twitter told the committee that its transparency reporting was under review, 
particularly in relation to disclosures, because 'some of the impacted states were 
reacting with hostility towards both our company and our employees, so we 
were also starting to face challenges around how we could do that work safely'.® 


AHRC recommended that one aspect of transparency should be that platforms 
are required to publicly disclose the content that they censor and it should be 
made an offence 'to censor content where that has not been publicly disclosed 
to users’. AHRC argued this measure would help to ensure that censorship 
(including extraterritorial censorship) does not unduly restrict the exercise of 
free speech in Australia." 


ASPI made a broader recommendation, that there should be an ‘explicit social 
contract ... mandating social media platforms to disclose state-backed influence 
operations and other transparency reporting to increase public awareness'.*” 


Meta and Twitter noted they have transparency measures to report where 
content is removed or restricted based on a legal request from a government or 
regulator, but noted they might not always know when a request is from a 
government actor. Mr Nick Pickles of Twitter told the committee: 


If it was someone in the Twitter app pressing a reporting button as a regular 
user, we might not know that person is from a foreign government.® 


Mr Pickles acknowledged pressure from some governments not to disclose that 
a content removal request had been made, and noted that strengthened 
transparency requirements would be a protective factor against such pressure: 
I think transparency is a phenomenal deterrent for pressure being applied. 
If a government knows that their request may be [relayed] to the individual, 


that makes the people submitting that request consider whether they want 
to do so.” 


Meta pointed to its transparency reports indicating that users can view content 
restrictions as a result of government requests. However, if a government 
request cites a breach of Meta's content policies, the request is not reported 


5t Meta, Submission 32, pp. 15-16. 


5 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 42. 


5 Australian Human Rights Commission, Submission 9, p. 16. 


5 Australian Strategic Policy Institute, Submission 13, p. 13. 


58 


Meta, answers to written questions on notice (1-11) 11 July 2023 (received 19 July 2023); 


Mtr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 48. 


5 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, p. 48. 


102 


6.77 


6.78 


6.79 


6.80 


6.81 


coming from a government, skewing the overall numbers of removal requests 
attributed to governments or state-actors. 


ASPI noted the lack of transparency from TikTok in relation to removed 

networks on its app: 
When you look at TikTok's disclosures, there is a claim that a network was 
taken down, but there is no information about what type of content it had, 
how it was done or any other information to actually verify and check to 
make sure they're not just silencing voices. For example, they took down a 
network operating out of Taiwan but didn't disclose what conversations or 
what topics those accounts were disclosing. That's concerning from an 
individual perspective, if the platform are taking down content or 
campaigns without giving a justification, as to whether it is proportional to 
the campaign itself. It's an important democratic principle to hold powerful 
platforms to account and do it transparently. 


Mr David Robinson, Director of Internet 2.0, noted that transparency around 
how companies make decisions was critical for individuals to make informed 
decisions: 

Consumers, in the end, will look at the risk-reward situation of their data 


and make decisions. But, if they can't make decisions because there's no 
transparency, then the first step in the process is pretty hard to do.® 


Ms Yagiu Wang of Human Rights Watch argued there is a role for governments 
to 'force companies to be transparent about what they are censoring, what they 
are suppressing, what they are promoting’ and said this could be done without 
adversely affecting how people use apps.® 


However, Meta noted that in relation to foreign interference 'it may not always 
be appropriate to have immediate transparency about steps taken to combat 
foreign interference. There are sometimes very good national security reasons 
why there may be a delay on that particular type of information, as I suspect 
security agencies may have advised this committee’. 


To address this, Meta advised the committee it has created partnerships with a 
handful of security expert organisations, which are given information that is not 
publicly available, such as ASPI. It noted that: 


&@ Mr Josh Machin, Meta, Committee Hansard, 11 July 2023, p. 10; Meta, Content restrictions based on local 


law, https://transparency.fb.com/data/content-restrictions/ (accessed 26 July 2023). 


& Mr Albert Zhang, Analyst, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, 


p. 21. 


62 Mr David Robinson, Director, Internet 2.0, Committee Hansard, 20 April 2023, p. 35. 


63 Ms Yaqiu Wang, Senior China Researcher, Human Rights Watch, Committee Hansard, 21 April 2023, 


p. 2. 


& Mr Josh Machin, Meta, Committee Hansard, 11 July 2023, p. 7. 


103 


6.82 


6.83 


6.84 


6.85 


6.86 


.. we will provide them with more detailed information about our take- 
downs than is available in the adversarial threat reports so that that can 
inform a lot of their research reports that they then provide publicly to the 
intelligence community about trends and patterns. 6 


The AHRC recommended the Australian Government should ‘establish clear 
and mandatory requirements and pathways for social media organisations to 
report suspected foreign interference activities’. 


ASPI recommended ‘regulation or at least a discussion about how we 
standardise and create better reporting mechanisms to increase transparency'.” 


Meta agreed with ASPI on this, and stated that ‘there has not been a 
benchmarking exercise or a standardisation of the metrics across all the 
companies that are signatories [to the code]. Meta pointed to a global 
organisation called the Digital Trust & Safety Partnership, which is conducting 
'a really deep-dive project particularly on this topic, about how you design 
transparency in ways to actually make it effective’. Meta suggested the outcomes 
of this project could be 'an important contributing factor to what the ACMA and 
policymakers might want to have in place as part of legislative reform in 
Australia’. 


The ACMA similarly noted that: 


We think there is still a way to go in terms of those reports. There's still very 
limited information about how platforms are going about measuring the 
effectiveness and impact of the measures they're reporting on under the 
outcomes of the code, and there is a lack of consistency. So, at the moment, 
we're not in a position to be able to assess, if you like, how measures that 
one signatory might be doing look against the impact of similar measures a 
different signatory might be doing.” 


However, the ACMA did acknowledge some improvements it had seen in 
reporting on Australian-specific data relating to misinformation, disinformation 
and CIB.” 


6 Ms Mia Garlick, Meta, Committee Hansard, 11 July 2023, p. 9. 


6 Australian Human Rights Commission, Submission 9, p. 8. 


67 Mr Albert Zhang, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 21. 


68 Mr Josh Machin, Meta, Committee Hansard, 11 July 2023, p. 7. 


© Mr Josh Machin, Meta, Committee Hansard, 11 July 2023, p. 8. 


70 Ms Cathy Rainsford, Australian Communications and Media Authority, Committee Hansard, 


12 July 2023, pp. 27-28. 


7t Ms Cathy Rainsford, Australian Communications and Media Authority, Committee Hansard, 
12 July 2023, pp. 27-28. 


104 


Partnerships with civil society 
6.87 The committee heard that partnerships between platforms and civil society were 


6.88 


6.89 


6.90 


6.91 


an important risk amelioration tool. These could be ongoing partnerships, such 
as fact-checking services, or could simply be that platforms provide the data 
necessary for expert organisations to undertake their research on foreign 
interference issues. However, while some platforms currently had such 
partnerships, there were ongoing concerns how effective they were, particularly 
in relation to data sharing. 


Meta outlined it was a major sponsor of the ASPI, which is among the small 
group of researchers it shares it shares information with about CIB takedowns. 
Meta also funded an ASPI review of information-for-hire, focused on the 
Asia-Pacific region.” 


Dr Andrew Dowse, Director of RAND Australia noted how difficult it is for 
researchers to identify incidents of foreign interference. Without access to social 
media networks’ internal identification data, researchers have to attempt to 
identify patterns in data and noted the need for greater funding: 
There are limited funding sources being provided in these areas. So in 
general we in RAND have been utilising US studies and US funding to be 
able to do it. I would dearly like to see the Australian government perhaps 
providing more sources of funding so we can do this research. At the 
moment all the research we've done in this area in Australia from a RAND 
perspective has been internally funded.” 


Professor Rory Cormac from the University of Nottingham noted the need for 
greater research to understand the scope of the problem, noting that states tend 
to count only in metrics—how many people were reached, or how many 
inauthentic newspaper articles were placed. Professor Cormac advised that this 
‘gives a misleading idea of the impact, because it doesn't tell you what the scope 
and the scale were’. Professor Cormac went on to detail some of the analysis that 
is required: 

Sometimes [states] work through legitimate actors. Sometimes they work 

through what were once called unwitting idiots. Sometimes they work 

through stooges. Sometimes they work through local influencers. So there's 

a whole spectrum, and we need to map that spectrum, that relationship 


between the state and the non-state actor or the conduit, to get a good sense 
of how direct or indirect this data is in order for us to counter that.” 


Professor Cormac later expanded on this and noted the need for greater analysis 
of the impacts of CIB: 


72 Meta, Submission 32, p. 15. 


73 Dr Andrew Dowse, Director, RAND Australia, Committee Hansard, 20 April 2023, p. 28. 


74 


Professor Rory Cormac, Director, Centre for the Study of Subversion, Unconventional Interventions 


and Terrorism, University of Nottingham, Committee Hansard, 20 April 2023, p. 37. 


105 


6.92 


6.93 


6.94 


It's not enough for us as governments to know how many people clicked on 
that. We then need to know: what did they do next? Did they click on 
Russian propaganda or terrorist propaganda or Chinese propaganda? Did 
they then get radicalised? Did they then click on something else? What was 
their journey? Being able to master that—that's big data and that's tough. 
That kind of behavioural change as a consequence needs to be measured.” 


Dr Stoltz advised that this approach would best be done in collaboration with 
classified intelligence collection to understand the intent of adversaries, so that 
‘we are informed through potentially classified information about what the core 
strategic intent of the adversary is, it means that our response can be managed 
in a more proportionate way and we don't get stuck in a loop of 
misunderstanding and reacting in inappropriate ways that causes a kind of 
escalation cycle'’.” 


Twitter flagged that it was open to an approach for providing data to academics 
where researchers could be 'accredited by governments, in some cases, or public 
institutions, as a form of vetting to actually protect the data itself from bad 
actors'.” Meta submitted that its ThreatExchange application programming 
interface (API) facilitates industry efforts to combat cyberthreats, through the 
threat signal sharing between security professionals.” 


Professor Cormac noted that to improve access to necessary data for analytical 
research, there had to be an international response. Governments could work 
together to persuade firms to share the data, either through the United Nations 
General Assembly, or via smaller groupings such as the Quadrilateral Security 
Dialogue (the Quad), the Association of Southeast Asian Nations (ASEAN) or 
‘or any other combination of multilateral groupings, in order to try and create 
cross-jurisdictional norms and standards that we're satisfied with, and then we 
can generate that scale to bring these companies into an alignment with an 
obligatory regime rather than one that is solely voluntary'.” 


Unverified accounts 


6.95 


Anonymity was also discussed as a concern. In regard to anonymity and 
identity shielding, this has benefits in that they can protect users' privacy, but 
they can also be weaponised to enable foreign interference. Some platforms' 
verification processes—or lack of—allow for fake, imposter, or multiple 


75 Professor Rory Cormac, University of Nottingham, Committee Hansard, 20 April 2023, p. 41. 


76 Dr William Stoltz, Private capacity, Committee Hansard, 20 April 2023, p. 41. 


77 Mr Nick Pickles, Twitter, Committee Hansard, 11 July 2023, pp. 42-43. 


78 Meta, Submission 32, p. 15. 


7 Professor Rory Cormac, University of Nottingham, Committee Hansard, 20 April 2023, p. 42. 


106 


6.96 


accounts to be created and operated by one user, which can then be used to 
conduct online foreign interference activities in an unmoderated way. 


Dr Andrew Dowse noted that allowing unverified accounts exacerbates the 
dangers of foreign interference via social media.*! 


Platforms and authoritarian states 
6.97 Many submitters and witnesses stressed that platforms which originate from 


6.98 


6.99 


authoritarian states pose additional security concerns that are not applicable to 
platforms that operate under free market principles within a liberal democracy. 
In particular, discussions centred on TikTok and WeChat.* 


CyberCX warned the committee that the collection and aggregation of the 
personal information of millions of Australians and the capacity for malign 
foreign actors to manipulate content consumed by Australians at scale is a 
heightened risk when using platforms that are linked to authoritarian 
governments, including TikTok and WeChat. As CyberCX pointed out, Chinese 
corporations are required by Chinese law to cooperate with Chinese 
government authorities which operate 'without the oversight and transparency 
mechanisms of rule-of-law democracies'.* 


ASIO highlighted the additional security concerns that authoritarian 
governments ‘are able to direct their country's institutions—including media, 
businesses and society—to support intelligence or foreign policy objectives in 
ways which are not acceptable in a democracy’. 


6.100 Internet 2.0 likewise argued that the 'free market principles' under which we 


allow companies to operate in a liberal democracy should not extend to 
authoritarian-based companies: 


They should not be allowed to gain profit and capital at the expense of our 
national security. Ultimately, they do not reside in our society. Social media 
companies that reside in our society will contribute and attempt to uphold 
democratic values. These companies should be defended against social 
media companies that align with our authoritarian competitors, because 


8 Australian Security Intelligence Organisation, Submission 2, p. 5. 


81 Dr Andrew Dowse, RAND Australia, Committee Hansard, 20 April 2023, p. 28. 


82 See, for example: Dr Seth Kaplan, Committee Hansard, 20 April 2023, p. 13; Mr Fergus Ryan, Analyst, 
Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, pp. 19, 21-22; 
Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 31; US Federal 
Communications Commission, Submission 4, p. 2; Australian Strategic Policy Institute, 
Submission 13, pp. 7-11; Rachel Lee, Prudence Luttrell, Matthew Johnson, John Garnaut, 
Submission 34, pp. 3-5. 


83 CyberCXx, Submission 16, p. 5. 


84 


Australian Security Intelligence Organisation, Submission 2, p. 4. 


107 


they flourish only as a result of our free-market principles and democratic 
system.® 


6.101 Ms Shanthi Kalathil, a former advisor on the US National Security Council, told 


the committee that these platforms are increasingly the propaganda tool of 
choice of authoritarian states: 


... network cross-border influence operations by authoritarian actors have 
grown in sophistication and effectiveness in recent years, shaping narratives 
and targeting democratic institutions during important geopolitical 
moments. These include but are certainly not limited to election periods. 
While not disavowing more traditional forms of propaganda, authoritarian 
regimes are increasingly using digital influence operations as a method of 
censorship and manipulation, flooding the information space with false or 
misleading narratives designed to crowd out independent voices and 
expertise. *° 


6.102 Ms Kalathil further advised the committee that 'we should not simply examine 


authoritarian links to social media platforms; we should put them in the context 
of the history and political systems from which they emerged, particularly with 
respect to the legacy of how those systems understand and manage information’ 
and noted that the implications of data collection by those authoritarian states 
was concerning, particularly in light of their security agencies attempting to 
harness big data for predictive policing.” 


6.103 ASPI used the above approach and put TikTok and ByteDance into their 


political context, by reminding the committee of the obedience to the CCP forced 
upon the ByteDance founder: 


For TikTok's parent company ByteDance, this authoritarian approach has 
included compelling the company's founder Zhang Yiming to make an 
abject apology in a public letter for failing to respect the Chinese Communist 
Party's ‘socialist core values’ and for ‘deviating from public opinion 
guidance'—one of the CCP's terms for censorship and propaganda.** 


6.104 ASPI advised the committee that this poses a regulatory challenge for 


85 


86 


87 


88 


government, such that platforms originating from authoritarian states do not 
face the same oversight in their home nations: 


Policymakers and legislators should ensure that when addressing the social 
media challenges (and broader technology risks) they do not 
disproportionately regulate Western technology platforms while ignoring 
technology platforms that originate from China or Russia. Democracies 
must not exacerbate the already unlevel playing field when our ultimate 


Internet 2.0, Submission 17, p. 3. 
Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, pp. 1-2. 
Ms Shanthi Kalathil, Committee Hansard, 20 April 2023, p. 2. 


Australian Strategic Policy Institute, Submission 13, p. 10. 


108 


objective is to be able to compete against the authoritarian regimes which 
are abusing technology to further their strategic interests.* 


6.105 In relation to WeChat, Dr Seth Kaplan, a US political expert, argued that 
platform is ‘basically a narrative machine for the CCP and what it wants to 
promote’. WeChat remains a wholly-owned subsidiary of Tencent with its 
headquarters in Shenzen, China.” 


6.106 Much is made about the importance of the WeChat platform to Chinese-heritage 
Australians: 
WeChat is essential to communication between Chinese Australians and 
their families, friends, and business partners in China. This is largely due to 
the fact that social media platforms such as WhatsApp and Facebook are not 
allowed in China. WeChat is a necessity, not a choice for many 
Chinese Australians.” 


6.107 Professor Wanning from the Australia-China Relations Institute (ACRI) at the 
University of Technology Sydney and Professor Haiqing, Professor of Media 
and Communications at RMIT, argued against the notion that the WeChat 
platform is heavily censored in favour of the CCP, submitting 'WeChat, like 
Facebook and Twitter, is a social media platform that carries wide-ranging and 
diversely sourced content; its ideological landscape is fragmented and 
contested’. ACRI's founding donor and chairman, Huang Xiangmo, was later 
banned from Australia on national security grounds.” 


6.108 The artist Badiucao disagreed and noted that because of the way WeChat 
operates in Australia, it enables the Chinese government 'to export its 
censorship outside of China regardless of local law or rights protection in 
Australian society'.” 


6.109 The Australian Electoral Commission (AEC) noted that although it monitors 
social media platforms as part of its work on election integrity, it does not 
monitor WeChat in the same way, because much of the conversation in WeChat 
occurs in closed channels. The AEC noted that on other platforms it also only 


82 Australian Strategic Policy Institute, Submission 13, p. 7. 


90 Dr Seth Kaplan, Committee Hansard, 20 April 2023, p. 12. 
°! Social media users in China use Weixin, operated by a Chinese entity and governed by Chinese 
law. WeChat in Australia is designed for users outside of mainland China. 


* Professor Sun Wanning and Professor Yu Haiqing, Submission 37, p. 2. 


°3 Professor Sun Wanning and Professor Yu Haiqing, Submission 37, p. 2. 


°4 Nick McKenzie and Chris Uhlmann, 'Canberra strands Beijing's man offshore, denies passport’, 
The Sydney Morning Herald, 5 February 2019; James Leibold, 'The Australia~-China Relations 
Institute doesn’t belong at UTS', The Conversation, 5 June 2017. 


3 Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 35. 


109 


monitors comments made in open channels, and it does not monitor individual 
conversations.” 


6.110 In relation to TikTok, warnings regarding the security of the platform have come 


from a variety of sources for many years. Most recently, in May 2023 the former 
head of engineering for ByteDance's US operations, Yintao Yu, alleged TikTok 
served as a propaganda tool for the Chinese government by suppressing or 
promoting content favourable to the country's interests. Mr Yu alleged the 
Chinese government monitored ByteDance's work from within its Beijing 
headquarters and provided guidance on advancing 'core communist values’ and 
maintained access to all company data, including information stored in the US.” 


6.111 In response to concerns around the platform, on 4 April 2023, the 


Australian Attorney-General, The Hon Mark Dreyfus KC MP, banned TikTok 
from being installed on government devices, except in limited circumstances. 
The ban has been implemented at a government level in other western countries 
including the US, the United Kingdom (UK), New Zealand, Canada and 
France.% 


6.112 The main concerns are China's national security law coupled with the data 


TikTok collects on its users. The 2017 law requires organisations and citizens to 
‘support, assist and cooperate with the state intelligence work', with experts 
saying while there is no definitive proof that China's government has used this 
law with TikTok, the type of data TikTok collects makes this a high risk.” 


6.113 The following sections outline some of the specific concerns with platforms such 


as TikTok and WeChat. 


CCP national security laws 
6.114 A key concern raised regarding platforms that originate from authoritarian 


96 


97 


98 


99 


states such as China, was that the data collected by those apps from millions of 
Australians can be misused to created targeted foreign interference 


Mr Tom Rogers, Electoral Commissioner, Australian Electoral Commission, Committee Hansard, 
12 July 2023, pp. 34-35. 


1 


Executive fired from TikTok's parent company ByteDance lays complaint against tech giant’, 


ABC News, 13 May 2023, Haleluya Hadero, 'Fired TikTok exec says Chinese government had access 
to app user data’ Sydney Morning Herald, 13 May 2023. 


The Hon Mark Dreyfus KC MP, 'TikTok ban on Government devices', Media release, 4 April 2023; 


Josh Taylor, 'What does TikTok's ban from Australian government devices mean for its future?', 
The Guardian, 4 April 2023. 


Josh Taylor, 'What does TikTok's ban from Australian government devices mean for its future?', 
The Guardian, 4 April 2023. See, for example: Simon Jiandan, Submission 36, pp. 1, 3 and 8; US Federal 
Communications Commission, Submission 4, pp. 1-5; AHRC, Submission 9, pp. 13-14; Rachel Lee, 
Prudence Luttrell, Matthew Johnson, John Garnaut, Submission 34, pp. 67-71. 


110 


campaigns.'!° Many submitters and witnesses noted that Chinese national 
security and data laws meant that private companies are required by Chinese 
law to assist national security agencies with any request they may make, and 
furthermore, that those requests must be kept secret. Ms Shanthi Kalathil stated: 


... [believe the structure of the party state in the People's Republic of China 
is such that, were the party to make demands on private companies, there's 
no legal or technical way for those companies to resist those demands. 


I would also say those companies in particular that you mentioned 
[Tencent and ByteDance] have already been named as particular champions 
by the state. They been designated as having a special relationship with the 
state, so they are in a bit of a different category; they are not like some of the 
smaller ones. Their entwinement and entanglement not just with the state 
but with the military and with overarching state priorities puts those 
companies in a special category. 1! 


6.115 Ms Kalathil further noted that large companies such as ByteDance and Tencent 
are required to have CCP cells operating within them.' 


6.116 ASPI noted of TikTok that: 


The enormous leverage that the CCP has over the company is what drove 
the company at the time to boost its army of censors by an extra 4,000 people 
(candidates with party loyalty were preferred) and it's what continues to 
motivate ByteDance to conduct 'party-building'’ exercises inside the 
company. 


6.117 Internet 2.0 noted further dangers that platforms such as TikTok and WeChat 
pose: 
We assess that social media companies which reside in our authoritarian 
competitors' orbit will not act in our democratic interests; if we attempt to 
compel them to remove disinformation, they can resist this as they balance 
the competing interests of the authoritarian regime. They can resist our 
sovereign interventions by hosting data, media, and their platforms outside 
of our jurisdiction. 14 
6.118 When asked about these Chinese national security laws and the safety of TikTok 
data from being shared with the CCP, the Australian Signals Directorate advised 


0 CyberCX, Submission 16, p. 5. 


01 Ms Shanthi Kalathil, Committee Hansard, 20 April 2023, p. 3. See also: Simon Jiandan, Submission 36, 
p. 8; Human Rights Watch, Submission 12, pp. 2-3; Internet 2.0, Submission 17 Attachment 1, p. 10. 


02 Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 3. 


% Australian Strategic Policy Institute, Submission 13, p. 10. 


% Internet 2.0, Submission 17, p. 6. 


111 


the committee that it had 'not seen technical controls that would provide a basis 
for technical advice that the risks of sharing data are adequately mitigated'. 105 


6.119 Furthermore, ASIO advised that ‘like any individual in a corporation or in 


government, if they [employees] have access to sensitive information or if they 
have the ability to propagate foreign interference, there will always be the 
potential that they'll be targeted'.1% 


6.120 Ms Yaqui Wang of Human Rights Watch also expressed doubt that companies 


like Tencent and ByteDance would not share data when asked by the CCP 
because 'their livelihood is hinged to the Chinese Communist Party'.!” 


6.121 Ms Lindsay Gorman of the Alliance for Securing Democracy advised the 


committee that: 


Our research has found that, despite the professed separation between the 
CCP and TikTok, PRC diplomats and state media accounts have gone to bat 
to TikTok, with messaging campaigns designed to paint the app in a benign 
light, hype up TikTok's popularity and the consequences of the ban, 
denigrate the US political system as hostile to business, and portray criticism 
of TikTok or China as xenophobic, often drawing on familiar tropes.' 


6.122 Ms Ella Woods-Joyce, Acting Director of Public Policy, Australia and 


New Zealand, TikTok, argued that TikTok Australia has 'never been asked for 
that user data and we would not provide it if we were asked’. Ms Woods further 
argued that data is not stored in China but did concede that did not mean data 
was not retrievable from China, as China based TikTok employees have access 
to data stored outside of China.1 


6.123 The claim that TikTok would not provide data was not seen as credible by many 


05 


06 


07 


08 


09 


110 


inquiry participants." Mr Brendan Carr, one of three United States Federal 
Communications Commissioners, noted that: 


Ms Abigail Bradshaw, Deputy Director-General, Australian Signals Directorate, Committee Hansard, 
12 July 2023, p. 3. 


Mr Mike Noyes, Deputy Director-General, Intelligence Service Delivery, Australian Security 
Intelligence Organisation, Committee Hansard, 12 July 2023, p. 8. 


Ms Yaqiu Wang, Human Rights Watch, Committee Hansard, 21 April 2023, p. 3. 


Ms Lindsay Gorman, Senior Fellow for Emerging Technologies, Alliance for Securing Democracy, 
German Marshall Fund, Committee Hansard, 21 April 2023, p. 8. 


Ms Ella Woods-Joyce, Acting Director of Public Policy, Australia and New Zealand, TikTok, 
Committee Hansard, 11 July 2023, pp. 22 and 23; TikTok, answers to questions on notice (4, 5, 6), 11 
July 2023 (received 21 July 2023). 


For example, see: Human Rights Watch, Submission 12, pp. 6-8; Internet 2.0, Submission 17 
Attachment 1, p. 10; Rachel Lee, Prudence Luttrell, Matthew Johnson, John Garnaut, Submission 34, 
p. 44, 47, 53 and 60-62. 


112 


The argument that somehow TikTok are going to stand up to the CCP is 
belied by their inability to do it at any point in time publicly. For instance, 
they've been asked in US media interviews whether they acknowledge the 
existence of the Uighur genocide that's taking place in Xinjiang. Their official 
on TV refused to address it. That same question was posed to their CEO 
when he testified here recently, and once again he declined to address it. If 
a TikTok official is not willing to say that the CCP is committing genocide 
with respect to Uighurs then that gives very little comfort that they would 
turn them down and say no to them when they do come to them for access. 
And it's almost separate from access; they're so intermingled here right now 
in terms of the data that is accessible from inside China, it's not clear that a 
formal ask would even be necessary in these circumstances." 


6.124 TikTok Australia did concede that it has engineers located within China who 


are working on the TikTok app, and further, that those workers were not under 
the direction or control of Mr Lee Hunter, the General Manager of Operations 
for TikTok Australia. It was later acknowledged that staff located in mainland 
China where the Chinese national security and data laws operate, do indeed 
have access to Australians’ data that is harvested by the TikTok app, and can 
also make changes to the operation of the algorithm which influences what users 
seen’ 


6.125 Mr Hunter, despite having made assurances that Australian TikTok users' data 


is safe, also acknowledged that he is just 'one of several spokespeople for TikTok 
in Australia’ and that he relies on the expertise of others to ensure his statements 
are factually accurate." 


Use of data TikTok data for CCP purposes 
6.126 Numerous reports exist that data collected by TikTok has made it into the hands 


of the CCP and has been put to use for political harassment and interference. 
For example, the AHRC submitted that 'ByteDance had used TikTok to track the 
physical location of multiple Forbes journalists who were reporting on the 
company as part of a covert surveillance campaign’ and an ‘investigation by 
BuzzFeed News that concluded China-based TikTok employees had access to 
US user data, and repeatedly accessed that data’. 


6.127 Mr Hunter, discussed the allegations of surveillance when they first arose, in an 


11 


12 


13 


14 


Mr 


Ms 


Mr 


Au 


opinion piece in the Daily Telegraph newspaper on 24 October 2022, stating that: 


Brendan Carr, Commissioner, United States Federal Communications Commission, 


Committee Hansard, 20 April 2023, p. 7. 


Ella Woods-Joyce, TikTok, Committee Hansard, 11 July 2023, p. 22 and Mr Lee Hunter, General 


Manager, Operations, Australia and New Zealand, TikTok, Committee Hansard, 11 July 2023, p. 25. 


Lee Hunter, TikTok, Committee Hansard, 11 July 2023, p. 25. 


stralian Human Rights Commission, Submission 9, p. 13. 


113 


Unfortunately, some of the public criticism TikTok has faced recently has 
not been based on fact but exaggeration, speculation and sometimes pure 
fabrication. 


Take for example a recent report that suggested 'TikTok parent ByteDance 
planned to use TikTok to monitor the physical location of specific American 
citizens’. 

The fact is ... TikTok has never been used to 'target' any members of the US 
government, activists, public figures or journalists, nor do we serve them a 
different content experience than other users. 


TikTok does not collect precise GPS [Global Positioning System] location 
information from US (or Australian) users, meaning TikTok could not 
monitor US users in the way the article suggested. 


6.128 Later when discussing the case with the committee, Mr Hunter said he disputed 
‘the characterisation that we spied on journalists’ and claimed it was the actions 
of 'rogue employees [who] are no longer with the business’. Mr Hunter 
informed the committee that strengthened policies meant this could not happen 
again, however, he did not acknowledge that in October 2022 he had declared 
the breach was not technically possible, and that 'TikTok could not monitor US 
users in the way the article suggested’. 


6.129 Mr Hunter did not respond to questions from the committee as to why he should 
be believed this time—given he had previously declared the breach could not 
occur and was proven wrong—and as to why he did not seek to correct the 
record. Mr Hunter's evidence to the committee lacked credibility and candour." 


6.130 Ms Woods-Joyce of TikTok Australia also discussed the current court case in 
which former employees disclosed that TikTok used its data to spy on users in 
Hong Kong, stating that 'we will be contesting the range of allegations that has 
been made in that matter'.1”” 


6.131 US Federal Communications Commissioner Brendan Carr told the committee 
that TikTok ‘presents an exceedingly unique threat to national security’ for two 
reasons, being surveillance and foreign influence. Commissioner Carr noted 
that in relation to surveillance 'TikTok operates as a very sophisticated 
surveillance technology’ and while TikTok claims it collects very little data: 

... that's not what the evidence indicates. TikTok collects everything from 
search and browsing history to keystroke patterns, and its terms of service 


reserve the right to get biometrics, including face prints and voice prints. For 
years, TikTok told regulators not to worry and that the data was not stored 


15 Lee Hunter, 'TikTok boss Lee Hunter asks for be measured on fact not fiction’, Daily Telegraph, 
24 October 2022. 


116 Mr Lee Hunter, TikTok, Committee Hansard, 11 July 2023, pp. 24-25. 
17 Ms Ella Woods-Joyce, TikTok, Committee Hansard, 11 July 2023, p. 30. 


114 


inside China. In some places it said that the data didn't even exist inside 
China. 


Flash forward to this past summer, and a BuzzFeed News report got internal 
TikTok communications that showed that in fact everything 'is seen inside 
China’. We've seen additional evidence pile on from there. For instance, 
TikTok denied a report that it—a China based team— was using the app to 
surveil the location of specific Americans. It said that that report lacked 
journalistic integrity. It turns out that that report was entirely accurate, and 
TikTok has now admitted that it used the app to surveil the locations of 
specific Americans—in fact, reporters that have been writing negative 
stories about TikTok and other reporters located outside the United States 
as well. Now the US Department of Justice and FBI [US Federal Bureau of 
Investigation] are looking into that exact type of conduct.!!8 


6.132 ASPI expressed similar concerns, citing data security and content manipulation, 
further noting that the leverage the CCP has over TikTok ‘exacerbates the former 
two risks and is unique to TikTok as a major mainstream social media app'.'” 


6.133 Internet 2.0 has conducted an in-depth analysis of the TikTok application and 
the data it collects, and found that: 


We've conducted code analysis on their location data twice, first last year 
and then secondly about two months ago. Their code basically accesses 
coarse and fine location and has a specific 'get long get lat’ string that in 
essence basically pulls the longitude and latitude from the GPS into the app. 
TikTok queries that location data specifically. The accuracy is debatable, but 
that's a technical discussion about whether it's five metres accurate or 
20 metres accurate. The fact that they actually pull the location is still there. 
It's another example of the lack of transparency and confusing response 
from TikTok, in my opinion. We just printed the code location requests and 
then they denied it. We said, "This is a picture.’ Anyway, they updated their 
code in the last six months. Previously they could get basically a horizontal 
and vertical location on the map. But they have updated their location data 
when we last analysed it, so now they can get bearing, speed and altitude. 
So if you're in a high-rise building, they can tell what floor you're on now. 
That wasn't previously in their code, last year.1 


6.134 David Robinson of Internet 2.0 advised that 'we saw no reason, in order to create 
an effective video platform, to have all that data’ and compared the practice to 
that of YouTube and Instagram, which are less invasive." Mr Robinson noted 
that: 


18 Mr Brendan Carr, United States Federal Communications Commission, Committee Hansard, 
20 April 2023, p. 6. 


19 Mr Fergus Ryan, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 18. 


2 Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 32. 


21 Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 32. 


115 


On an even basis, with a transparency scoring system, TikTok is the worst 
app that we have published in social media. 1?2 


6.135 In response, Ms Woods-Joyce of TikTok said that the report contains 'a range of 
information that is not necessarily accurate’ but was not specific as to what she 
claimed was not correct.!” 


Manipulation of content algorithms 

6.136 Another concern raised by inquiry participants was the use of TikTok by the 
CCP to further its propaganda, including through the manipulation of content 
algorithms or ‘heating’ buttons. 


6.137 In relation to foreign influence, Commissioner Carr noted that: 


... the CCP's propaganda arm set up TikTok accounts and, unlike other 
social media, did not disclose the state media affiliation of those accounts. 
Those accounts targeted US politicians for criticism ahead of our most recent 
mid-term elections—accounts that saw millions and millions of views on 
those videos. 14 


6.138 Ms Lindsay Gorman of the Alliance for Securing Democracy noted that 
'TikTok's heating button, for example, reportedly allows employees to manually 
make specific content go viral’ and further noted that if the CCP were to direct 
TikTok to heat certain content, 'it would be extremely difficult to discern this 
manipulation’ .!5 


6.139 ASPI submitted that leaked documents have revealed that TikTok instructed 
moderators to censor videos that ‘mention Tiananmen Square, Tibetan 
independence, or the banned religious group Falun Gong’. TikTok conceded this 
occurred but insisted 'those documents don't reflect its current policy and that 
it had since embraced a localised content moderation strategy tailored to each 
region’. 176 


6.140 ASPI further noted that: 


In 2022, TikTok blocked an estimated 95% of content previously available to 
Russians, according to Tracking Exposed, a nonprofit organization in 
Europe that analyses algorithms on social media. In addition to this mass 
restriction of content, the organisation also uncovered a network of 
coordinated accounts that were using a loophole to post pro-war 
propaganda in Russia on the platform. In other words, at the outset of 


22 Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 33. 
23 Ms Ella Woods-Joyce, TikTok, Committee Hansard, 11 July 2023, p. 25. 


Mr Brendan Carr, United States Federal Communications Commission, Committee Hansard, 
20 April 2023, p. 6. 


°5 Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 8. 


2% Australian Strategic Policy Institute, Submission 13, p. 9. See also: Ms Ella Woods-Joyce, TikTok, 
Committee Hansard, 11 July 2023, pp. 29-30. 


116 


Putin's invasion of Ukraine, TikTok was effectively turned into a 24/7 
propaganda channel for the Kremlin.'”” 


6.141 ASPI advised the committee that TikTok has the ability to detect political speech, 


because it 'monitors key words in posts for content related to elections so that it 
can then attach links to its in-app election centre’. ASPI cited experiments 
conducted by non-profit group Accelerate Change, which found that using 
certain political words in TikTok videos decreased their distribution by 66 
per cent. ASPI further advised that in 2020, US TikTok executives had noticed 
that views for certain political content creators were dropping 30 to 40 per cent. 
The executives later 'found out that a team in China had made changes to the 
algorithm to play down political conversations about the election’.!” 


6.142 Ms Woods-Joyce of TikTok told the committee that 'TikTok is not moderated 


based on political sensitivities’. When asked whether TikTok had done so in the 
past, she conceded that 'in the past that we have not always made the correct 
moderation decisions’ but did not specify exactly what changes had been made 
to ensure that did not occur again. This attempted evasion of straightforward 
questions, which was a consistent feature of Ms Woods-Joyce's evidence before 
the committee, reflected poorly on her as a witness. !” 


6.143 However, ASPI highlighted that manipulation of content is not limited to 


TikTok. ASPI noted an example in February 2023, where "Twitter chief executive 
Elon Musk rallied a team of roughly 80 engineers to reconfigure the platform's 
algorithm so his tweets would be more widely viewed’. ASPI advised that there 
is ‘clearly a need for all social media companies to be more transparent about 
how changes to their algorithms affect the content users receive'.'° 


Evading oversight 
6.144 Commissioner Carr also raised concerns with the manner in which TikTok 


127 


128 


129 


130 


engages with regulation and oversight: 


When a senior TikTok official—I believe the COO [Chief Operating 
Officer] —was testifying here in our Senate a few months ago they were 
asked point-blank, 'Do you share sensitive US user data with personnel— 
TikTok or ByteDance—in Beijing that are themselves members of the CCP?' 
That official declined to answer that question. I think a lot of these concerns 
could have been put to rest if they had answered pointedly and either said 


Australian Strategic Policy Institute, Submission 13, p. 9. 
Mr Fergus Ryan, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 19 
Ms Ella Woods-Joyce, TikTok, Committee Hansard, 11 July 2023, pp. 29-30. 


Australian Strategic Policy Institute, Submission 13, p. 10. 


117 


no or, frankly, perhaps said, 'Yes, and here are the protections put in place.’ 
The evasive nature of these answers over years is deeply concerning. '*! 


6.145 Mr David Robinson of Internet 2.0 raised similar concerns. His organisation 


highlighted a number of concerns with TikTok's data collection, and noted in 
their response that: 


TikTok have never actually been transparent. TikTok have never said, 
‘Internet 2.0 is wrong because of this piece of code and it actually does this 
and this,’ and printed lines of their code in a transparent way. They've 
always just called us names and spent a lot of money on anti campaigns. 
From my perspective, every other social media company that we engage 
with has come back and qualified their position. Companies like Proton and 
Telegram, when asked, qualified their position and explained exactly what 
their things do. TikTok have never done this with evidence. !°? 


6.146 Mr Robinson compared the TikTok response to Proton, saying that Proton ‘just 


sent us the GitHub, and we analysed that and it came out exactly the same 
because it's a transparent way to do things’ and further noted in relation to 
TikTok's response that 'when people deny stuff, normally you've found their 
sensitive spot'.133 


6.147 This evasive nature was evident in the manner in which TikTok's Australian 


executives responded to questions posed by the committee at a public hearing 
on 11 July 2023. When asked a simple question, Ms Woods-Joyce avoided 
agreeing with the premise that ByteDance is a Chinese company, despite the 
submission stating TikTok is proud of ‘our company's Chinese heritage’. 
Further, Ms Woods-Joyce avoided answering whether Bytedance is 
headquartered in China, stating that 'ByteDance has operations around the 
world’, later conceding the existence of 'offices in China’.'*4 


6.148 These answers are consistent with news reports that leaked ‘internal documents 


31 


33 


35 


Mr 


show TikTok is actively instructing employees to "downplay the China 
association" to deflect growing media scrutiny over the video-sharing app's 
Beijing-based owner’. 


Brendan Carr, Commissioner, United States Federal Communications Commission, 


Committee Hansard, 20 April 2023, p. 7. 
32 Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 31. 
Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 32. 


34 Ms Ella Woods-Joyce, TikTok, Committee Hansard, 11 July 2023, p. 21; TikTok, Submission 30, p. 2. 


Thomas Barrabi, ‘Leaked TikTok memo told employees to downplay the China association’, 
NY Post, 27 July 2022. 


118 


6.149 This is further highlighted by the March 2023, resignation of a senior ByteDance 
executive from the Australian board of TikTok, amid the viral video platform's 
efforts to distance itself from its Chinese parent company. 


Data safety 
6.150 This issue of data collection by the CCP has been one of increasing concern to 
the global intelligence community. Mr Richard Moore, head of the UK's 
intelligence agency, MI6, recently warned that: 
China has added to its immense datasets at home by hoovering up others 
abroad, and the Chinese authorities are not hugely troubled by questions of 


personal privacy, or individual data security. They're focused on controlling 
information and preventing inconvenient truths from being revealed.” 


6.151 Ms Yaqiu Wang of Human Rights Watch noted that all social media platforms 
gather data, but while most do so for the purposes of 'selling you more things’, 
Chinese-based companies were subject to the control of the CCP, which ‘has 
political goals beyond profits'.138 


6.152 Internet 2.0 argued for actions to keep data safe from authoritarian regimes: 


As social media companies are the primary producer of high quality social, 
psychological, political, military, and economic data, liberal democracies 
must move to defend this data by limiting the access to it by authoritarian 
regimes. 13 


6.153 The approach of data localisation, where user data is housed in databanks 
outside of mainland China, is currently being considered by platforms in the 
European Union (EU; Project Clover) and the US (Project Texas). Details were 
outlined in Chapter 3. Experts advised this committee that a similar approach 
could be taken here, but qualified that it would not be a 'silver bullet’ solution. 


6.154 Mr David Robinson of Internet 2.0 noted that while a single mechanism would 
not work, he believed that 'some form of local data storage is required' because 
‘we lose the ability to control how that data is regulated once it leaves our 
shores’. Mr Robinson further explained the difficulties in regulating offshore 
data: 


... the Australian Privacy Act is limited to Australian waters, basically. As 
soon as that data leaves Australia, it's up to you to have an alliance or an 


3% Max Mason, 'ByteDance executive resigns from TikTok Australia board’, Australian Financial 
Review, 21 March 2023. 


37 Alexander Martin, 'Head of MI6 warns that China is setting "data traps" for partners’, The Record, 
19 July 2023. 


38 Ms Yaqiu Wang, Human Rights Watch, Committee Hansard, 21 April 2023, p. 6. 


3 


No} 


Internet 2.0, Submission 17, p. 5. 


119 


agreement with the other country that your law still applies. If you sell the 
data to China and it's in China, Chinese law applies.“ 


6.155 Mr Robinson noted the difficulties this presents during an election, where if data 


is sitting in a country that doesn't cooperate with Australia, the ability to have it 
taken down quickly is reduced and the statements have longer to have an 
impact. If data is sitting in Australia or the US, it can likely be taken down within 
hours. 


6.156 Mr Robinson further advised that Australia should look to data collection laws 


in the EU: 


... the GDPR [General Data Protection Regulation] is probably a better 
system of regulating how data is used. The ability of Western social media 
companies to collect and sell users' data in Europe is far less than in 
Australia and the US—so I can't buy sophisticated advertising data easily in 
European jurisdictions as I can in Australia and the US, because of the way 
the act works.142 


6.157 Ms Shanthi Kalathil noted that data collection is not only occurring via social 


media platforms. She advised that Chinese participation in smart city platforms 
in a number of countries also provided an opportunity for data collection, and 
in particular the gaming sector is a place where significant amounts of data can 
be collected, but that sector ‘frequently does not get included in the kinds of 
conversations that we're having here today'.'* 


6.158 Ms Kalathil agreed that data localisation may help to mitigate the risk, but noted 


that 'you can't use primarily a technical or legal solution to what ultimately is a 
political problem’. 


6.159 Commissioner Carr concurred that data localisation [Project Texas in the US] 


40 


41 


42 


43 


44 


45 


would not provide sufficient protections, and cited a relevant news article: 


The Buzzfeed news article got leaked internal audio from TikTok DC 
[District of Columbia] officials saying that, even after Project Texas was put 
in place, ‘It remains to be seen if product and engineering'— meaning 
Beijing—'would continue to have access to the data.’ If TikTok officials 
themselves don't believe that Project Texas is actually going to safeguard 


data against access from inside China, I think we should take their word for 
it. 


Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 34. 
Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 35. 
Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 35. 
Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 4. 


Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 4. 


Mr Brendan Carr, United States Federal Communications Commission, Committee Hansard, 
20 April 2023, p. 8. 


120 


6.160 Commissioner Carr recommended the best approach would be a ban or genuine 


divestiture, for example where ByteDance would be forced to sell TikTok to a 
non-Chinese, mainland US company. 


6.161 ASPI also expressed doubt at the usefulness of data localisation: 


TikTok will always say that TikTok user data is stored in Singapore or in the 
United States. That is really immaterial if that data continues to be accessed 
from Beijing. 


Impact on Chinese-language media 


6.162 A key concern of experts was the chilling effect that WeChat can have on 


independent Chinese-language media. Dr Kaplan noted that these independent 
media outlets ‘because of advertising and WeChat and possibly because they 
want to do business in China, are self-censoring completely’. 


6.163 Human Rights Watch raised similar concerns that local Chinese-language media 


self-censors so their content will be allowed on WeChat: 


Then, as a local news website operator, because your account is on WeChat, 
you have to think about what can be published on WeChat. So you 
self-censor ... A diaspora outlet that caters to the diaspora has to go through 
Beijing's censors. Even what's going on in Australia is censored by Beijing. 
That's the news side.” 


6.164 Dr Kaplan, informed the committee that it is not just federal issues of concern, 


but that in the US 'the state level may be more vulnerable than the federal level’. 
Dr Kaplan noted that 'WeChat is managing information, helping to mobilise 
Chinese speakers and then seeking coalition partners among the 
non-Chinese-language-speaking civil society, and all this, basically, is direct 
interference in the politics of the country'.!° 


TikTok bans 
6.165 On 17 March 2022, New Zealand's Parliamentary Service announced it was 


blocking TikTok from all parliamentary devices. This followed a ban in 
November 2022 preventing members of New Zealand's Defence Force from 
having the app on government issued phones, joining the Ministry of Education, 
Ministry of Foreign Affairs and Trade, Department of Prime Minister and 


20 April 2023, p. 8. 
47 Mr Fergus Ryan, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 22. 
48 Dr Seth Kaplan, Committee Hansard, 20 April 2023, pp. 12 and 17. 


4 Ms Yaqiu Wang, Human Rights Watch, Committee Hansard, 21 April 2023, p. 4. 


5° Dr Seth Kaplan, Committee Hansard, 20 April 2023, p. 12. 


46 Mr Brendan Carr, United States Federal Communications Commission, Committee Hansard, 


121 


Cabinet, Corrections, Police, Treasury, Ministry of Justice, and Ministry of 
Primary Industries.1! 


6.166 Canada's Federal Government banned TikTok on government-issued devices in 


February 2023.12 


6.167 When questioned on the decisions to ban TikTok and security concerns raised 


by the governments of the US, Canada, France, the UK, the 
European Commission, New Zealand and Denmark Ms Woods-Joyce of TikTok 
said 'we don't believe there's any evidence to support the view that TikTok is in 
any way a national security threat, as might be implied by some of the 
commentary about us'.153 


6.168 However, when the same question was immediately posed to Mr Will Farrell, a 


TikTok US Security Officer, he gave an opposite response and said 'we've never 
pushed back on the concerns' and then clarified that meant 'we choose not to 
argue about the concerns’. Mr Farrell was portrayed to the committee as a 
technical expert who could answer questions about the operation of the app, but 
was frequently not able to do so. TikTok's decision to make available witnesses 
to the committee who were not able to assist with obvious questions indicates 
they did not intend to genuinely engage in the committee process. 


6.169 The Australian Signals Directorate provided an extensive outline to the 


151 


152 


153 


154 


committee on the nature of the advice it gave the Australian Government; advice 
which was a considerable factor in the decision to ban the app from 
government-issues devices: 


ASD's [Australian Signal Directorate's] technical advice centres on its 
analysis of the business model which is employed by TikTok which, like 
other social media platforms, operates on the basis of collecting user 
information. That information and data collection includes data, user 
generated content and device data. The application can also identify other 
applications in use on the device and any browsing activity undertaken 
within the TikTok web browser. The other data may include users' names, 
email addresses, phone numbers, contacts, photos, user IDs [identifications], 
ad [advertising] identifiers and data stored in the device clipboard while 
TikTok is in use. Device data may include SIM card and IMSI [international 
mobile subscriber identity] numbers, device type and model, language, time 
zone, unique device IDs, running of installed apps, IP [internet protocol] 


Tess McClure, 'New Zealand to ban TikTok from government devices’, The Guardian, 17 March 2023; 
Thomas Manch, 'Defence Force orders TikTok to be wiped from phones, as government agencies 


grapple with data risks’, Stuff, 4 March 2023. 


Alex Hern, the Guardian, 'Canada bans TikTok on government devices over security risks’, 
1 March 2023. 


Ms Ella Woods-Joyce, TikTok, Committee Hansard, 11 July 2023, p. 30. 


Mr Will Farrell, Security Officer, TikTok US Data Security Inc, Committee Hansard, 11 July 2023, 
pp. 30-31. 


122 


addresses, telecommunication provider details and details of the devices on 
the same network. 


Finally —and not so much technical but associated with the technical risks — 
is the risk of foreign ownership. I heard the committee comment before on 
the operation of the Chinese national intelligence law which requires that 
citizens, companies and organisations cooperate, and there is capacity to ask 
for that cooperation not to be disclosed.1> 


6.170 Several Australian Government departments have also implemented 
restrictions on WeChat, including the Department of the Prime Minister and 
Cabinet, the Department of Foreign Affairs and Trade, and Home Affairs. 15 


Bans or divestment 

6.171 There was disagreement among expert witnesses as to whether the best security 
mitigation for platforms that originate from authoritarian states was usage bans, 
standards-based regulation or divestment of platforms to companies that would 
be wholly subject to local laws. 


6.172 Dr Seth Kaplan argued against an outright ban on WeChat because it would be 
too difficult to implement. Dr Kaplan instead pointed to setting standards via 
regulation, but noted that it would be difficult for WeChat to meet those 
standards ‘given the way China operates and the way Tencent is related to the 
government’. Dr Kaplan further noted that WeChat could not be divested in the 
same way that TikTok could be.157 


6.173 ASPI did not go so far as to call for a ban of such platforms and applications, but 
recommended ‘bespoke legislation that deals with TikTok and any other 
emerging major social media apps from authoritarian countries'.' 


6.174 Mr David Robinson of Internet 2.0 argued against banning specific apps because 
companies could quickly use the source code to make a new app and argued 
that applying ‘legislation and regulation to the software and the code and how 
it acts is more important than the specific company'.'” 


155 Ms Abigail Bradshaw, Australian Signals Directorate, Committee Hansard, 12 July 2023, p. 3. 


156 


Gus McCubbing, ‘Banning WeChat would ‘damage’ democracy, experts say', Australian Financial 


Review, 4 May 2023; Josh Taylor, ‘Australian government resists blanket WeChat ban despite 
restrictions by multiple departments’, The Guardian, 28 April 2023. 


15 Dr Seth Kaplan, Private capacity, Committee Hansard, 20 April 2023, pp. 13-14. 
158 Mr Fergus Ryan, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 19. 


15 Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 33. 


123 


6.175 Ms Yagiu Wang of Human Rights Watch also argued in favour of 


standards-setting legislation, which included shutdown 
non-compliance. 160 


clauses for 


6.176 Ms Lindsay Gorman of the Alliance for Securing Democracy argued for forced 


divestiture of TikTok, given its large user base and incorporation into the wider 


information environment: 


That makes it very, very difficult to contemplate something like a ban. That 
is why it's my view that a forced divestiture, whereby the concerns could be 
partially mitigated by the removal of TikTok's Chinese ownership by 
ByteDance, would allow TikTok to keep operating in democracies without 


that overwhelming threat of foreign influence and interference.16! 


6.177 However, Ms Gorman stressed that this approach should be taken in 


conjunction with establishing legislated safety frameworks for future apps and 


platforms 'so that we can get ahead of these threats before they become one of 


the most popular apps in the country and in the world, and we can address them 


head-on before getting into the scenario that is not a great one that we find 


ourselves in today'.162 


6.178 Mr Kenny Chiu, a Canadian MP who was subjected to foreign interference 


during an election, argued against ‘just abruptly banning WeChat from all 


usage, because the shock that could go around the community and the diaspora 


would be huge and could sever many ties that they have, be they business ties 


or, even worse, familial ties with family members’. He advised that western 


liberal democracies should instead try to ‘encourage our citizens, through 


education and persuasion, to diversify and not rely on one single app'.'@ 


6.179 The artist Badiucao argued in favour of standards-based regulation that would, 


at its essence, protect free speech: 


I do believe Australians should have regulation to make companies like 
WeChat follow our laws, respect our way of life and value our freedom of 
speech. If they fail to obey those regulations then punishment or even 
banning should be a possible option in order to protect the rights of the 
people who are living in Australia. This has nothing to do with racism or 
xenophobia. This is actually to defend universal human rights. This is also 
how the Chinese diaspora can benefit from this mechanism because now we 
don't need to be subject to the Chinese government's tyranny and control. 
Regardless of whether you're using Chinese, English, Mandarin or 
Cantonese, with any platform we shall have the right to express ourselves 


160 Ms Yaqiu Wang, Human Rights Watch, Committee Hansard, 21 April 2023, p. 3. 


161 Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 9. 


162 Ms Lindsay Gorman, Alliance for Securing Democracy, Committee Hansard, 21 April 2023, p. 9. 


16 Mr Kenny Chiu, Private capacity, Committee Hansard, 21 April 2023, p. 18. 


124 


instead of being censored, controlled and intimidated by this foreign 
government in China.' 


164 Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 35. 


7.1 


7.2 


7.3 


7.4 


Chapter 7 
Building the capacity of civil society 


Crucial to a comprehensive and coordinated approach to countering foreign 
interference through social media is inclusion of, and collaboration with, civil 
society. A common recommendation across many submissions was the need to 
improve the capacity and resilience of both individuals and civil society to 
respond to disinformation, degradation of public trust in democratic 
institutions, and foreign interference through social media.! 


In addition to government and platform-based solutions discussed in 
Chapters 4 to 6 this chapter discusses the role for non-government institutions 
and civil society to address foreign interference through social media. 


Initiatives to build capacity and resilience in civil society should at times be 
supported and/or funded by government, with the groundwork primarily 
undertaken by non-government bodies, specifically through: 


e independent fact checking, expert centre monitoring, research and solutions 
development; 

e civil litigation; 

e building resilience in communities through public and school education; 

e impartial and independent reporting through mainstream media; and 

e improving knowledge, capacity and community cohesion in diaspora and 
culturally and linguistically diverse (CALD) communities. 


Nevertheless, Reset Australia warned against overly relying on social media 
end-user empowerment, arguing for a more comprehensive government and 
platform response to foreign interference through social media rather than 
shifting the burden to citizens and communities.” 


A role for civil society organisations, expert centres and researchers 


7.5 


Fact checkers are engaged directly by social media platforms to mitigate against 
disinformation, as discussed in Chapter 6. However, beyond these, other civil 
society-based researchers provide additional independent commentary and 
scrutiny to help inform and highlight disinformation and foreign influence. 


See, for example: Information and Influence University Partnership (comprising University of 
Adelaide, University of Melbourne and University of New South Wales), Submission 28, p. [3]; Meta, 
Submission 32, p. 18; Department of Home Affairs, Submission 1, pp. 4-5; Australian Security 
Intelligence Organisation, Submission 2, p. 7; Australian Human Rights Commission Submission 9, 
p. 9; News and Media Research Centre, University of Canberra, Submission 21, pp. 4-5. 


Reset Australia, Submission 26, pp. 2 and 7-8. See also: CyberCX, Submission 16, pp. 9-10. 


125 


126 


7.6 


7.7 


7.8 


7.9 


This unique role played by independent civil society organisations (such as fact 
checkers and expert centres) and researchers was highlighted by submitters to 
the inquiry, with Reset Australia calling these bodies 'the canaries in the coal 
mine sounding the alarm for emerging threats to Australian society’. 
The importance of these services was reiterated by Mr Kenny Chiu, a former 
Canadian politician, who recommended that: 

Australia should perhaps provide a seal of approval to certain 

non-government organisations that provide fact-checking services to the 

constituents in their own language, be it Persian, Russian or even Chinese 

and other languages that are commonly exploited. This would be effective 

in providing a way for the diaspora community to at least realise that they 


are being used and manipulated and that their interests are actually being 
hurt by these predatory regimes that are infiltrating us.4 


The Defence and Security Institute within the University of Adelaide suggested 
that civil society expert centres (such as the Defence and Security Institute) have 
the ability to ‘play a significant role in the development of a national capability 
to detect, defend, and disrupt social influence operations both online and 
offline’ and contribute to the development of policy and public education 
responses.” 


As discussed in Chapter 6, social media platforms provide some data and tools 
to help improve their transparency. However, as highlighted in a joint 
submission from University technical expert centres, 'the technical capacity to 
detect and analyse disinformation operations is concentrated in the hands of the 
platforms and a few specialised research and monitoring bodies'. The 
submission highlighted that although this capacity is limited it is crucially 
important, with the resulting information enabling civil society to 'monitor 
platform and government action against ongoing or real-time disinformation 
operations'.6 


Professor Rory Cormac of the University of Nottingham noted that while he 
viewed fact checking as important, he advised that it has limitations — people 


Reset Australia, Submission 26, p. 2; CyberCX, Submission 16, pp. 4 and 9, Australian Strategic Policy 
Institute, Submission 13, p. 12. 


Mr Kenny Chiu, Private capacity, Committee Hansard, 21 April 2023, p. 16. 


Emphasis in the original submission. Defence and Security Institute, Submission 3, pp. 3 and 7. 
See also: Australia Institute, Submission 31.2: Foreign Interference through Social Media inquiry 
(46" Parliament), p. 20. 


University of New South Wales (NSW) Allens Hub for Technology Law and Innovation, Deakin 
University Centre for Cyber Security Research and Innovation and Institute of Electrical and 
Electronics Engineers (IEEE) Society on Social Implications of Technology (University Centres Joint 
Submission), Submission 19, pp. 6-7. See also: Australia Institute, Submission 31: Foreign Interference 
through Social Media inquiry (46th Parliament), p. 4., p. 2. 


127 


7.10 


7.11 


7.12 


7.13 


7.14 


may not believe the fact checkers, particularly those 'who are inherently 
sceptical of the state’.” 


Submitters suggested that utilisation of civil society-based expertise could be 
more inclusive and draw on a greater number of expert voices, work more 
innovatively across disciplines, potentially place more pressure on platforms 
and government to address disinformation and ‘prevent the appearance of 
government and platforms acting like "Big Brother", secretively and only 
selectively cracking down on some disinformation while tolerating others'.’ 


The Information and Influence University Partnership went further, 
recommending the establishment of a new organisation to coordinate 
monitoring and operational responses to malicious information threats, 
drawing on a pool of expert, multidisciplinary academic and industry partners.? 


However, several witnesses highlighted that access to platforms’ data (in a way 
that preserves privacy) can be challenging.® Mr Josh Machin from Meta 
explained that: 
... many folks within the industry are broadly supportive of transparency 
and working with academics, but there can be very challenging 
considerations to work around, particularly from a privacy perspective ... 
it's an area in which we continue to work very hard and make more 
information available to support academics, experts and policy makers in 
scrutinising content on our services." 


Submitters and witnesses also advised that adequate funding is essential to 
enable civil society organisations, independent researchers and expert centres to 
effectively fulfill this monitoring, research and solutions development role.!” 


While Australian Government agencies, such as the Department of Defence and 
the Australian Research Council, already provide some funding to expert 
centres to conduct relevant research, Reset Australia contended that 'they suffer 
from extremely limited resourcing’. CyberCX called for the 
Australian Government to facilitate more independent research into 


7 Professor Rory Cormac, Director, Centre for the Study of Subversion, Unconventional Interventions 
and Terrorism, University of Nottingham, Committee Hansard, 20 April 2023, p. 40. 


8 University Centres Joint Submission, Submission 19, pp. 6-7; Defence and Security Institute, 
University of Adelaide (Defence and Security Institute), Submission 3, pp. 2-3 and 7. 


° Information and Influence University Partnership, Submission 28, pp. [4-5]. 


° Improved transparency and access to platform data is discussed in Chapter 6. Reset Australia, 
Submission 26, p. 2; CyberCX, Submission 16, p. 19. 


1 Mr Josh Machin, Head of Public Policy, Australia, Meta, Committee Hansard, 11 July 2023, p. 8. 
2 Reset Australia, Submission 26, p. 2; CyberCX, Submission 16, p. 9. 


3 Defence and Security Institute, Submission 3, pp. 2-3 and Reset Australia, Submission 26, p. 2. 


128 


‘investigating, exposing and analysing social media interference and malign 
influence’, for example through grant funding." 


7.15 Social media platform Meta, likewise supported engagement with industry and 


civil society experts as well as technical research to improve policy and 
operational responses and the detection of malicious threats. 


Litigation 
7.16 Australian Supporters of Democracy in Iran discussed the use of courts and 


litigation by civil society as a potential means to address disinformation 
campaigns and the distribution of hate material. It also noted that Australian 
policy and governance appears to be under-developed in this area, with civil 
law primarily impacting on social media 'mainly through libel and defamation 
cases’, rather than action relating to foreign interference.' 


Building resilience through public education 


7.17 Many submitters raised the need for robust public education campaigns to 


counter to disinformation and foreign interference through social media, with a 
particular focus on improving information and media literacy, and empowering 
individuals to manage their online interactions." 


7.18 Witnesses drew attention to the wider context of rising distrust in public 


institutions, more polarised and extreme societal and political divisions, and an 
increase in conspiratorial thinking." 


7.19 Furthermore, the Law Council of Australia highlighted the growing market for 


‘disinformation-for-hire' which ‘differs from genuine political campaigns 
because it is covert, deceptive, and manipulates public discourse to undermine 
democratic participation’. 


CyberCx, Submission 16, p. 9. 
Meta, Submission 32, p. 17. 
Australian Supporters of Democracy in Iran, Submission 23, pp. 4-5. 


See, for example: News and Media Research Centre, University of Canberra, Submission 21, pp. 5 
and 17; Law Council of Australia, Submission 27, p. 3; CyberCX, Submission 16, pp. 4 and 8; 
Australian Tibetan Community Association, Submission 31, p. 5; Department of Home Affairs, 
Submission 1, pp. 4-6; Australian Human Rights Commission, Submission 9, pp. 9-10; Information 
and Influence University Partnership, Submission 28, pp. [2-3]; RAND, Submission 11, p. 3; 
Ms Mia Garlick, Regional Director of Policy, Meta, Committee Hansard, 11 July 2023, p. 9. 


See, for example: News and Media Research Centre, Submission 21, p. 5; CyberCX, Submission 16, 
pp. 2 and 7-8; Reset Australia, Submission 26, pp. 1-2; Australian Muslim Advocacy Network, 
Submission 24, p. [3]; Australian Human Rights Commission, Submission 9, pp. 5-7; RAND 
Australia, Submission 11, p. 2. 


Law Council of Australia, Submission 27, p. 2. 


129 


7.20 


7.21 


7.22 


7.23 


The News and Media Research Centre of the University of Canberra called for 
information and media literacy measures to be considered within this bigger 
picture with a quotation from the North Atlantic Treaty Organization's Centre 
for Media Literacy: 

"Democracy stands or falls on people. The challenge for democracies is to 

find ways to preserve the freedoms that come with more access to 

information, while protecting against the threats that come with it. The most 

democratic way to address this challenge is teaching [members of] society 

to be wiser information consumers and producers through critical thinking 

and a pedagogy that empowers them to evaluate, analyse, and choose 


critically whether to act on information. Media literacy education facilitates 
this critical thinking and thereby, risk management".”° 


The Department of Home Affairs (Home Affairs) outlined its current 
engagement and education initiatives, including in a variety of community 
languages, through the Australian Values social media channels, and in 
partnership with other government agencies, non-government organisations 
and community members. The Australian Cyber Security Centre also monitors 
threats and provides security advice to citizens and government to ensure 
account holders are aware of social media risks and their social media accounts 
are secured.?! 


Social media platforms, including Meta and TikTok, have committed to 
promoting and investing in digital literacy education, and provide fact checkers, 
tools, policies and processes to help their users make informed decisions about 
content, to identify authentic sources of information and stay safe.” 


CyberCX submitted that the public is not sufficiently well-informed about the 
risks and responses associated with foreign interference through social media: 


The information available to Australian citizens regarding foreign 
interference orchestrated through social media is patchy and generic, 
despite the key role citizens, the private sector and state and local 
governments play as vectors and victims of interference. 


Citizens and private organisations lack the expertise, resources and access 
to understand the risks of every social media platform they engage with. 
This problem is exacerbated by the opacity and complexity of platforms’ 
software and terms of service and, in some cases, links with authoritarian 
governments.” 


20 News and Media Research Centre, Submission 21, pp. 4 and 5. 


21 


Department of Home Affairs, Submission 1, pp. 4-6; Department of Home Affairs, answers to 


questions on notice (no. 7), 12 July 2023 (received 18 July 2023). 


22 TikTok, Submission 30, pp. 1, 4-5 and 10; Meta Australia, Submission 32, pp. 14-16 and 18; 
Digital Industry Group Inc., Submission 36, p. 2. 


23° CyberCX, Submission 16, p. 8. 


130 


7.24 Public education campaign models used overseas, as discussed in Chapter 2, 


could provide models for similar Australian campaigns. Submitters to the 
inquiry recommended a range of public education approaches to ‘improve 
digital literacy and awareness, as well as to build resilience to misinformation 
and disinformation’ and foreign interference through social media,” including: 


e increased visibility or exposure of the scale of foreign interference in 
Australia;5 

* more comprehensive and ‘actionable, specific advice’ regarding individual 
platforms; 

e how communities and individuals can report instances of foreign 
interference through social media, including through workshops;”” 

e education and guidance materials on values, critical thinking, how users can 
identify and counter misinformation and disinformation, how algorithms 
use personal data to tailor online experiences and how users can protect 
themselves on social media; and 

e accessible and tailored education materials to meet the needs of all 
Australians, including across age demographics and CALD communities.” 


7.25 Mr Albert Zhang of ASPI highlighted the role that government has in providing 


24 


25 


26 


27 


28 


29 


information to support civil society through public education: 


The key takeaway and what the government could do is to actually be more 
transparent and offer more information where individuals, society or 
businesses can't do the research or do the due diligence to verify the 
information itself. This is really pertinent when it comes to foreign based or 
state backed disinformation or foreign interference. The individual is not 
going to be able to detect whether an authoritarian security agency is 
running an influence campaign against them. So, in those cases, it's really 


Law Council of Australia, Submission 27, p. 3; Information and Influence University Partnership, 
Submission 28, pp. [2-3]; Australian Strategic Policy Institute, Submission 13, pp. 14-15. 


Law Council of Australia, Submission 27, p. 3. 


CyberCx, Submission 16, pp. 7-8; Ms Vicky Xu, Senior Fellow, Australian Strategic Policy Institute, 
Committee Hansard, 21 April 2023, pp. 35-36. 


Mr Kalsang Tsering, President, Australian Tiebetan Community Association, Committee Hansard, 
21 April 2023, p. 26. 


CyberCx, Submission 16, pp. 7-8; Australian Tibetan Community Association, Submission 31, p. 5; 
Australian Human Rights Commission, Submission 9, pp. 9-10 and 12; University Centres Joint 
Submission, Submission 19, Attachment 1, p. [4]. 


Australian Human Rights Commission, Submission 9, p. 10; eSafety Commissioner, Submission 10, 
p. [2]; Cyber CX, Submission 16, p. 4. 


131 


7.26 


7.27 


7.28 


important for government to disclose their intelligence or disclose their 
findings to the public who are being targeted.*° 


The News and Media Research Centre suggested better engagement with media 
professionals and associations, peak professional bodies and community sector 
groups with expertise in media and information literacy training and in the 
provision of provide public education programs and resources. The centre 
further recommended funded research into the impacts of new media 
technology and how best to deliver media and information literacy.3 


At the April 2023 public hearing, Dr Andrew Dowse from RAND Australia 
drew attention to a training package it is developing for a government client 'to 
help people identify, understand and protect themselves from foreign 
interference ... efforts to increase media literacy are critical in relation to that 
challenge, but they are not the only solution’. 


Similarly, Mr Richard Salgado, Director, Law Enforcement and Information 
Security, Google, noted that such government-run campaigns are not a panacea 
for the problem of foreign interference and disinformation on social media. 
Mr Salgado stated that: 


I would say my experience with this and what we have seen so far would 
suggest that there is probably no single voice that's going to be effective; it 
has to be a chorus of voices. There are going to be plenty of people who are 
not going to believe a government agency when they say it, just as there 
would be plenty who won't believe it if a company or security researchers 
were to say it. I don't think that there is an answer in the terms of a single 
voice that will be heard by all those who you want the message to get to.” 


Electoral public education 


7.29 


There has not been any identified foreign interference compromising the 
integrity of the 2022 Australian federal election. However, there are alleged 
examples of foreign interference in other democratic countries, most notably 
Russian interference in the 2016 United States' Presidential election and 
2022 midterm elections.™* As noted by Internet 2.0: 


3 Mr Albert Zhang, Analyst, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, 
p. 24. 


31 


News and Media Research Centre, Submission 21, p. 17. 


32 Dr Andrew Dowse, Director, RAND Australia, Committee Hansard, 20 April 2023, pp. 27 and 30. 


33 


Mr Richard Salgado, Director, Law Enforcement and Information Security, Google, Committee 


Hansard: Foreign Interference through Social Media inquiry (46 Parliament), 30 July 2021, p. 13. 


34 Australian Electoral Commission, Submission 8, p. 2; RAND Australia, Submission 11, pp. 2-3; 
Australian Strategic Policy Institute, Submission 13, pp. 2 and 4; Dr William Stolz, Senior Fellow, 
National Security College, Australian National University, Submission 18, pp. 15-16; Reset 
Australia, Submission 26, pp. 5-6; Rachel Lee, Prudence Luttrell, Matthew Johnson and John 


132 


... elections are a strategic opportunity to influence our democratic process. 
They [Australia's authoritarian competitors] believe that it is to their benefit 
if the voting population have less confidence in the true results of elections. 
By conducting divisive campaigns, they seek to divide our societies, to 
weaken us, and to fracture our uniting values.’ 


7.30 The Information and Influence University Partnership further explained the 


dangers of foreign interference in electoral processes, including through social 
media: 


Foreign interference can thwart democratic participation in nation-building. 

. Disinformation operations can be used broadly to normalise anti- 
democratic views and actions, microtargeted to cultivate extremist views, 
and even to radicalise some segments of the population. Such operations 
may recruit and incite radicalised individuals and groups to engage in anti- 
democratic activities and assaults on the institution of democracy itself. 
Moreover, public displays of anti-democratic behaviours (and foreign 
operations to fuel them) may undermine the legitimacy of democracy as an 
institution, erode the citizens’ trust in the apparatus of democracy— 
parliament, government, and judiciary—and cause disillusionment, 
disenchantment, and apathy, thereby threatening democratic 
participation. 


7.31 As such, public education in relation to electoral matters was a specific area of 


interest raised by several witnesses. The Australian Electoral Commission 
(AEC) highlighted that: 
Determining the success of any parliamentary election is ensuring that not 


only is every ballot counted, re-counted and results certified, but that 
Australians have confidence in the outcome.” 


7.32 The AEC noted that Australia's laws regulate electoral and political 


35 


36 


37 


38 


communications, however they do not, in general, regulate truth in electoral 
advertising: 

. with one limited exception, it does not regulate truth in electoral 
communication. Furthermore, the High Court has found there is an implied 
freedom of political communication in the Commonwealth Constitution 
that limits the scope of the Parliament to make laws restricting political 
communications.’ 


Garnaut, Submission 34, pp. 4-5; Professor Rory Cormac, University of Nottingham, Committee 
Hansard, 20 April 2023, p. 38. 


Internet 2.0, Submission 17, p. 6. 
Information and Influence University Partnership, Submission 28, p. [2]. 
Australian Electoral Commission, Submission 8, p. 1. See also CyberCX, Submission 16, p. 2. 


Australian Electoral Commission, Submission 8, p. 2. See also Ms Sally Pfeiffer, Acting First Assistant 
Secretary, Counter Foreign Interference, Department of Home Affairs, Committee Hansard, 
12 July 2023, pp. 8-9. 


133 


7.33 


7.34 


7.35 


7.36 


7.37 


Nevertheless, a survey conducted by the AEC found that 80 per cent of those 
surveyed: 
... believed the Australian Government has a responsibility to educate 
people about disinformation on social media. In addition, 48 per cent of 
those surveyed reported seeing false or misleading content on social media 
(an increase from 38 per cent at benchmark) and 67 per cent agreed that 
groups/individuals deliberately spread false information online about 
voting.” 
Witnesses drew attention to preparations for the 2022 federal election and the 
range of measures adopted by the AEC. These included a nationwide education 
and advertising campaign, establishing a disinformation register, working with 
platforms, including the development of a Statement of Intent for the Federal 
Election 2022, referring disinformation to online platforms for review and 
responding directly to disinformation online (for example through Twitter). 


In March 2023, it was reported that the AEC ‘is looking to go a step further and 
set up information sharing arrangements with Australian Associated Press 
(AAP) Fact Check, RMIT FactLab and RMIT ABC Fact Check' in the lead up to 
the upcoming referendum on an Indigenous Voice to Parliament.“ 


Platforms also have a role in 'the promotion of authoritative sources of 
information, partnering with fact checking organisations, and collaborating 
with the Australian Electoral Commission’ to address election-related 
disinformation and to promote authoritative AEC content, including in the lead 
up to The Voice referendum.“ 


TikTok drew attention to its election-related measures, including its work with 
partners such as AAP FactCheck, as well as prohibitions on political advertising, 
which in 2023 are being extended to restrict solicitations for campaign funding 
and political party donations.* It also highlighted its in-app election guide 
which 'provided detailed, authoritative information on the election process, 


3 Australian Electoral Commission, Submission 8, p. 3. 


4 Department of Home Affairs, Submission 1, p. 4. See also the Australian Human Rights Commission, 


Submission 9, p. 12; Australian Strategic Policy Institute, Submission 13, p. 9; Digital Industry Group 
Inc., Submission 35, pp. 4-5. 


4 Sam Buckingham-Jones and Mark Di Stefano, 'AEC eyes tie-up with fact-checkers for Voice 


r 


eferendum', Australian Financial Review, 19 March 2023. 


42 Department of Infrastructure, Transport, Regional Development, Communications and the Arts, 
Submission 7, p. 2. See also DIGI, Submission 35, p. 5; Ms Mia Garlick, Regional Director of Policy, 
Meta, Committee Hansard, 11 July 2023, p. 2. 


43 TikTok, Submission 30, pp. 5 and 6. 


134 


including information on where and how to vote and preferential voting 
explainers developed by the Commission [AEC]'.“# 


Australian Electoral Commission's ‘Stop and Consider’ campaign 


7.38 


7.39 


7.40 


7.41 


7.42 


For the 2022 federal election, the AEC established a strong digital presence and 
expanded on its 2019 'Stop and Consider' public education campaign, aimed at 
'encouraging voters to stop, check and consider the source of electoral 
information they are consuming'.® 


The AEC also placed advertising and other media placements across social 
media platforms, digital displays and search term advertising, as well as 
information in over 20 languages. 


The AEC observed that its approach was successful, and that its: 


... digital presence [was] widely recognised as one of the most forthright 
and informative from a government agency. Delivering on the reputation 
management principles, the AEC took an approach focusing on being 
human in tone, swift and regular in reply, and knowledgeable. This 
approach helped solidify our digital presence as the authoritative voice on 
electoral processes, providing a defence to Australian democracy from the 
threat of disinformation.” 


The AEC attributed the campaign's success to the fact it directly addressed 
disinformation online and its friendly, often humorous approach which 
engaged the public. Even the Washington Post reported on the campaign— 
quoting political scientist Ariadne Vromen—'their meme game is pretty strong 

. and the informal language is really important. It’s personalized. It’s using 
everyday norms of engagement. And that is the kind of thing that people will 
notice and will share’. 


The AEC's very deliberate approach to inform and engage the public and 
encourage reporting of disinformation resulted in numerous social media users 


4 TikTok, Submission 30, p. 6. 


45 Australian Electoral Commission, Submission 8, p. 3. 


46 Australian Electoral Commission, Submission 8, p. 4; Mr Tom Rogers, Electoral Commissioner, 
Australian Electoral Commission, Committee Hansard, 12 July 2023, p. 36. 


47 Australian Electoral Commission, Submission 8, p. 3. 


48 


Michael E Miller and Frances Vinall, "The Twitter account defending Australian democracy’, The 


Washington Post, 14 May 2022. See also: Cait Kelly, "Firm but friendly": how the AEC Twitter 
account is winning friends and influencing people’, The Guardian, 11 February 2022; Michelle Elias, 


"Leave the eggplant off": How the AEC is engaging online to counter fake claims about voting’, 
SBS News, 16 March 2022. 


135 


7.43 


reporting and tagging misleading content, opening the door to the AEC 
stepping in with correct information.” 


In their submission the Law Society of New South Wales Young Lawyers 
recommended that the Electoral Integrity Assurance Taskforce be obliged to 
produce a periodic report on foreign interference through social media in 
Australian elections, stating that 'such a report would support vigilance among 
the Australian public as to what potential threats they may encounter online in 
upcoming elections’. 


School-based education 


7.44 


7.45 


7.46 


7.47 


Regarding media literacy, the Joint Standing Committee on Electoral Matters 
(Electoral committee) previously recommended in its Report on the conduct of the 
2016 federal election and matters related thereto that: 
. increased social media literacy, as part of a strengthened civics and 
electoral education curriculum, is a vital component in facing the challenges 
posed by this new social media environment. Australians must be better 


equipped to critically discern and judge any media which seeks to influence 
their voting behaviour." 


The Electoral committee subsequently recommended that: 


Recommendation 30 | ... the Australian Government consider ways in 
which media literacy can be enhanced through education programs that 
teach students not only how to create media, but also how to critically 
analyse it. 


Recommendation 31 | ... the Australian Electoral Commission examine 
ways in which media literacy can be incorporated into a modern, relevant 
civics education program.” 


A number of submitters to this inquiry highlighted the importance of 
school-based information and media literacy campaigns to address 
disinformation and foreign interference through social media. 


Ms Emily Moseley from ASPI highlighted the effectiveness of social media 
disinformation education in schools in northern Europe, stating that 'in 
particular, younger generations that are more influenced by social media are 


4 Australian Electoral Commission, Disinformation register: 2022 Federal Election, 10 January 2023 
(accessed 21 July 2023). 


50 Law Society of New South Wales Young Lawyers, Submission 33, p. 8. 


51 Joint Standing Committee on Electoral Matters, Report on the conduct of the 2016 federal election and 
matters related thereto, November 2018, p. 61. 


52 Joint Standing Committee on Electoral Matters, Report on the conduct of the 2016 federal election and 
matters related thereto, November 2018, pp. xxviii-xxix. 


136 


7.48 


7.49 


7.50 


7.51 


7.52 


coming up in the generation and learning and determining which news sources 
are relevant or what to look for in terms of combatting disinformation’. 


Home Affairs noted that in 2022-23 the Australian Government provided 
$6 million funding over three years to the Alannah and Madeline Foundation 
to: 
... develop and deliver digital and media literacy education products for 
primary and secondary school students. These products will be made freely 
available to every Australian primary and secondary school, improving 


digital literacy and helping students to be critical, responsible and active 
citizens online.™4 


In 2022, the Australian Capital Territory Education Directorate also funded 
News and Media Research Centre to co-create primary school educational 
resources, successfully demonstrating the value of civic online reasoning 
education." 


However, the News and Media Research Centre of the University of Canberra 
suggested that the current information literacy education model has failed given 
the wide variations between state and territory institutional responses and the 
teaching strategies used are commonly 'outmoded' and 'ineffectual'.* 


Submitters, including University technical expert centres and the 
Australian Human Rights Commission (AHRC), recommended curriculum 
changes to ensure that information and media literacy is included in Australian 
schools and adapted to the current environment.” The News and Media 
Research Centre further recommended appropriate education and development 
programs for teachers to equip them with the required knowledge and skills.” 


In discussing what content could be included in a school setting, Principle Co 
proposed teaching critical thinking and media literacy skills to students, which 
would allow them to 'sceptically question what [they] see and read to develop 
informed opinions from an early age', as well as examining the impacts of 


53 Ms Emily Mosley, International Cyber Policy Centre Coordinator, Australian Strategic Policy 
Institute, Committee Hansard, 20 April 2023, p. 24. 


54 Department of Home Affairs, Submission 1, p. 6. 


5 News and Media Research Centre, Submission 21, p. 9. 


56 News and Media Research Centre, Submission 21, p. 6. 


5 University Centres Joint Submission, Submission 19, pp. 2-3, 6 and 16 and Attachment 1, p. [1]; 
Australian Human Rights Commission, Submission 90: Foreign Interference through Social Media 
inquiry (46 Parliament), p. 10. 


58 News and Media Research Centre, Submission 21, p. 16. 


137 


psychological processes such as cognitive miserliness, cognitive dissonance, 
confirmation bias, motivated reasoning, and repetition error.” 


Mainstream media 


7.53 


7.54 


7.55 


7.56 


7.57 


Witnesses recognised that public broadcasters and mainstream media also have 
public education responsibilities to provide reliable, accurate and apolitical 
information about current events and political matters, with ASPI arguing that 
this information forms 'critical infrastructure’ for informed decision-making.” 


Discussing the declining trust in institutions, the News and Media Research 
Centre noted 'when people think the mainstream media is not holding 
industries and governments to account, they view it as a mouthpiece for elite 
interests, and may be more likely to accept information that challenges 
conventional beliefs'.*! 


Social media is increasingly the source of news content for many Australians. 
Dr Seth Kaplan, a US political expert, told the committee 'there are significant 
numbers of people using it [social media] for news and for information and are 
being exposed to that. I think that has great implications for your social cohesion 
and the trust of your government in those vulnerable communities’. Dr Kaplan 
further argued that for foreign language speakers the news they consume is 
based on a single dominant view.” 


This view was reiterated by Mr Kenny Chiu, a former Canadian MP: 


I believe that in the multicultural society that we live in, respecting 
everybody's rights for the flow of information, unfortunately some of the 
diaspora community members are living in relative information isolation, 
and therefore that presents a huge opportunity for these regimes such as the 
CCP [Chinese Communist Party] to exploit and spread disinformation 
among them ... they don't know what they don't know, and they have no 
way of fact-checking in their comfortable and preferred language.® 


In order to address the risks posed to Australia's democracy by foreign 
interference through social media, Human Rights Watch made a range of 
recommendations including promoting independent and professional 
journalism (in Chinese), investing in training and similar programs, and 


5 Principle Co, Submission 25: Foreign Interference through Social Media inquiry (46* Parliament), p. 8. 


60 Australian Strategic Policy Institute, Submission 13, p. 7. See, for example: Department of Home 
Affairs, Submission 1, p. 5; Special Broadcasting Service, Submission 14, pp. 1-4. 


61 News and Media Research Centre, Submission 21, p. 5. See also: Australian Muslim Advocacy 
Network, Submission 24, p. [4]. 


62 Dr Seth Kaplan, Private capacity, Committee Hansard, 20 April 2023, p. 15. See also: Sora Park, 
Caroline Fisher, Kieran McGuinness, Jee Young Lee, and, Kerry McCallum, Digital news report: 
Australia 2021, June 2021, p. 10; Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 37. 


63 Mr Kenny Chiu, Private capacity, Committee Hansard, 21 April 2023, p. 16. 


138 


7.58 


investing in other open-source technologies to provide other channels of 
communication to enable communities to more easily bypass censorship. 


Principle Co similarly noted that governments need to 'avoid undermining’ the 
work of journalists, stating that: 


Strong safeguards should be developed to avoid future repeats of recent 
police raids on journalists, unlawful accessing of metadata to identify a 
journalist's source, and a spree of new national security legislation which 
criminalises journalistic activity. 6 


Diaspora communities 


7.59 


7.60 


7.61 


7.62 


This section considers how communities and individuals—in particular 
diaspora communities —can be empowered to improve their resilience against 
foreign interference through social media, as well as mitigating the impacts of 
disinformation, information campaigns, amplification and manipulation, 
propaganda and censorship. 


The AHRC advised the committee of its concerns that foreign interference is 
increasing tensions and polarisation in Australia, writing that it: 
... is increasingly disturbed by the role misinformation and disinformation 


plays in diminishing social cohesion, promoting distrust and division, and 
undermining principles of equality, respect and human dignity ... 


Where social media is utilised by foreign actors to sow discontent and 
division in pursuit of their own agendas, disinformation can have a serious 
impact on the rights and freedoms of all Australians.” 


This view was supported by ASPI, which submitted that 'social media has 
created an unprecedentedly connected global community but this extensive 
reach has also allowed malign actors to intimidate, coerce and threaten violence 
beyond their borders, often with impunity and anonymity’'.” It is also impacting 
on Australian's relationships with their family and friends overseas.® 


As outlined in Chapter 4, the Australian government has taken various steps to 
counter foreign interference through social media, including by way of social 


64 Human Rights Watch, Submission 12, p. 8. See also: Ms Melissa Harrison, Submission 5: Foreign 
Interference through Social Media inquiry (46 Parliament), p. 26; Badiucao, Private capacity, Committee 
Hansard, 21 April 2023, p. 37. 


6 Principle Co, Submission 25: Foreign Interference through Social Media inquiry (46" Parliament), p. 5. 


6 Australian Human Rights Commission, Submission 9, p. 7. 


67 Australian Strategic Policy Institute, Submission 13, pp. 3 and 15. See also: Dr William Stoltz, 


National Security College, Australian National University, Submission 18, pp. 17-18. 


68 Australian Tibetan Communities Association, Submission 31, pp. 2-3; Mr Kalsang Tsering, 
President, Australian Tiebetan Community Association, Committee Hansard, 21 April 2023, 
pp. 24-26; Ms Vicky Xu, Senior Fellow, Australian Strategic Policy Institute, Committee Hansard, 
21 April 2023, p. 34. 


139 


cohesion, community liaison and outreach programs, media campaigns, 
publication of fact sheets by Home Affairs, ASIO and Australian Federal Police 
(AFP). Ms Sally Pfeiffer expanded on the work of Home Affairs: 


... the Department of Home Affairs has a network of community liaison 
officers who worked very closely with culturally and linguistically diverse 
communities on a range of issues relating to Home Affairs activities, 
including some engagement on issues such as foreign interference. Those 
engagements are very important to us and we work very closely with those 
communities to make sure they have awareness of the potential for risks of 
foreign interference, and then what they can do to manage them.” 


7.63 In July 2023, Home Affairs advised that since February 2023, engagements 


relating to foreign interference had been conducted with the Arab, Cambodian, 
Chinese, Eritrean, Indian, Iranian, Vietnamese, Kurdish, Russian, Rwandan and 
Ukrainian communities.” 


7.64 Mr Stephen Nutt, Commander of Special Investigations with the AFP told the 


committee of the importance of this type of work: 


. my personal view is that the best strategy to defend against foreign 
interference is through high community and agency awareness and also 
knowledge of how to report it. If it's reported, we're able to understand it. 
And once we're able to understand it, we can work to disrupt and look at 
vulnerabilities that need to be corrected not only on individual case basis, 
but at more system level. So it's absolutely key.” 


7.65 This community outreach approach has been welcomed, with Dr Dowse from 


69 


70 


71 


72 


RAND Australia telling the committee: 


I know that the Department of Home Affairs has been looking specifically 
at communities where English is not the first language, and I think that is a 
very intelligent priority because a lot of diaspora communities have their 
own sources of information which may not be mainstream and might not be 
traditional social media either. So I think understanding where those 
diaspora communities get their news and their information is important. It 
may change from diaspora to diaspora. I think understanding that is 
important if we're going to have a harmonious society, whether that's 
ideological or related to where the ethnic origins of portions of our society 
are. I think, to start with, that understanding where those potential sources 
of division might come from, including the sources of information and the 
influences ... and then understanding how you can balance that where 
there's concern about unfactual sources of information is an important 


See, for example: Mr Stephen Nutt, Commander, Special Investigations, Counter Terrorism and 
Special Investigations Command, Australian Federal Police, Committee Hansard, 12 July 2023, 
pp. 18 and 22. 


Ms Sally Pfeiffer, Department of Home Affairs, Committee Hansard, 12 July 2023, p. 7. 


Department of Home Affairs, answers to questions on notice (no. 7), 12 July 2023 
(received 18 July 2023). 


Mr Stephen Nutt, Australian Federal Police, Committee Hansard, 12 July 2023, p. 22. 


140 


priority. So I was really happy to see that Home Affairs has got that as a 
priority.” 
7.66 The eSafety Commissioner also emphasised the targeted nature of the support 
it provides: 

eSafety aims to provide support to a range of communities and groups, 
particularly to those most at risk of online harm. Our regulatory schemes 
can assist individuals who may be susceptible to foreign interference, such 
as diaspora groups, those with low digital literacy, and minority groups 


who may be the target of cyber abuse and illegal activity. These schemes 
intersect on a range of issues to provide multiple avenues of support. 


In addition to targeted misogynistic abuse and gendered disinformation, 
women in the public eye who challenge autocratic leaders, traditional male 
power structures or human rights and gender issues tend to attract more 
organic and coordinated vitriol online.”4 


7.67 Chapter 6 expanded on the steps platforms have undertaken to improve 
transparency and the awareness of disinformation within diaspora communities 
and the public. For example, platforms publishing enforcement and threat 
reports, state media account labelling, % and Meta’s development of a 
policy-focussed paper on misinformation and disinformation amongst diaspora 
groups with emphasis on Chinese language.” 


7.68 However, other witnesses argued that more needs to be done. ASPI argued that 
law enforcement and intelligence agencies should increase their community 
engagement to raise awareness, establish a reporting scheme to ‘counter 
transnational repression’, and reassure targeted individuals and groups.” 


7.69 The Australian Tibetan Communities Association argued for better consultation 
with civil society, and affected communities by government,” including 
regarding the development of new measures to counter foreign interference 
through social media and drafting new legislation.® 


73 Dr Andrew Dowse, Director, RAND Australia, Committee Hansard, 20 April 2023, p. 30. 
74 eSafety Commissioner, Submission 10, p. [2]. 


73 Meta Australia, Submission 32, pp. 15-16; Ms Emily Mosley, International Cyber Policy Centre 
Coordinator, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 23. 


7% TikTok, Submission 30, pp. 6 and 9; Mr Fergus Ryan, Analyst, Australian Strategic Policy Institute, 
Committee Hansard, 20 April 2023, p. 20. 


7” Meta Australia, Submission 32, p. 14. 
78 Australian Strategic Policy Institute, Submission 13, p. 15. 


7 Australian Muslim Advocacy Network, Submission 24, pp. [18-19]; Australian Tibetan 
Communities Association, Submission 31, p. 5. 


8 Australian Tibetan Communities Association, Submission 31, p. 5. 


141 


7.70 Specifically, regarding the Chinese-Australian community, the Council on 


Middle East Relations urged the Australian Government to establish and 
maintain a presence on Chinese-language social media platforms in order to 
engage Chinese-Australians and Taiwanese-Australians and provide resources 
to assist these groups in identifying misinformation and disinformation.*! 
The China Policy Centre likewise encouraged such outreach to 
Chinese-Australians, stating that it would serve three key purposes: 


First, it enables the better communication of government policy, strategy 
and priorities with the opportunity to hear community feedback ... 


Second, regular and effective outreach by the Australian Government can 
assist with early identification of community concerns, and new challenges 
and threats. Chinese-Australians are the main targets of China's 
propaganda, misinformation, cyber surveillance, and censorship efforts 
through social media. Regular outreach provides an avenue to counter 
Chinese-language misinformation, especially in relation to government 


policy. 
Third, the support of Chinese-Australians is crucial for an effective strategy 
addressing China's foreign interference efforts. * 


7.71 The AHRC noted challenges to rights to freedom from discrimination and 


freedom of expression citing harassment, surveillance and censorship of 
Australians by social media. The AHRC argued that: 


Transparency is the key to ensuring that censorship (including 
extraterritorial censorship) does not unduly restrict the exercise of free 
speech in Australia. With respect to the last of these examples, the 
Commission would endorse the recommendation previously made by the 
ASPI International Cyber Policy Centre that governments ‘should mandate 
that all social media platforms publicly disclose, in detail, all the content 
they censor and make it an offence to censor content where that has not been 
publicly disclosed to users’. 


7.72 Dr Bruce Arnold of the University of Canberra submitted that an informed 


81 


82 


83 


populace was in a significantly better position to be resilient. Dr Arnold 
observed that ‘it is ... viable to emphasise community self-help, with 
participants in social media platforms being alert to the likelihood of 
misrepresentation and equipped to discern that statements are malicious’. 
Dr Arnold further noted that ‘ultimately a savvy Australian population—with 


Council on Middle East Relations, Submission 25: Foreign Interference through Social Media inquiry 
(46 Parliament), p. 4. 


China Policy Centre, Submission 4: Foreign Interference through Social Media inquiry (46 Parliament), 
p. 3. 


Australian Human Rights Commission, Submission 9, p. 16. See also: Human Rights Watch, 
Submission 12, p. 8. 


142 


access to information through a public transparency regime—is the best defence 
against foreign interference and misbehaviour by domestic actors'.** 


7.73 Ms Shanthi Kalathil agreed, telling the committee: 


We are really going to have to work on the long-term education and 
awareness raising of not just populations but different institutions of society 


I think the Nordic countries, for instance, have several decades of history of 
building education and awareness about information into their educational 
systems from a young age. There are certainly examples we can look to 
around the world that can provide, if not a blueprint, some kind of 
indication about what might work and what might not work. So I think we 
need to do some serious looking at some of these examples from around the 
world to understand this problem better.* 


7.74 Regarding what practical activities individuals can undertake immediately, 


84 


85 


86 


Principle Co encouraged Australians to: 


e follow a wide spectrum of sources; 

e seek our diversity of perspective, including by making sure that you are not 
just following voices that you naturally agree with; and 

e ask questions, such as: who produced this content, what reaction is it 
seeking, and how did the information get to you?* 


Dr Bruce Arnold, Submission 7: Foreign Interference through Social Media inquiry (46" Parliament), p 7. 
See also John Abdelmalek, Kyron Johnson, Michael Barberio, and Mathew Bubica, with Dr James 
Scheibner, Submission 40: Foreign Interference through Social Media inquiry (46" Parliament), p. 20. 


Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, pp. 4-5. 


Principle Co, Submission 25: Foreign Interference through Social Media inquiry (46" Parliament), p. 8. 


Chapter 8 
Committee view and recommendations 


Overall committee view 


8.1 


8.2 


8.3 


8.4 


8.5 


8.6 


1 


In authoritarian states, citizens are subjected to government repression in the 
form of censorship, where people are restricted from freely discussing issues 
that would enable them to make fully informed social and political choices. 
Such censorship is anathema to the values of democratic states such as 
Australia. This provides authoritarian countries with an asymmetric advantage 
because they can readily censor narratives within their own country while 
simultaneously exploiting the openness of democratic societies to push their 
agendas offshore. 


Because authoritarian governments cannot directly control the information 
environment in democratic states via overt censorship, they seek to control the 
information environment by flooding our online spaces with disinformation 
that skews public debate, undermines trust in our democratic institutions, 
establishes narratives that favour the interests of the perpetrating state and 
make it difficult for the casual observer to separate truth from fiction. 


We cannot allow this rising authoritarianism to contaminate our democracy and 
undermine our social cohesion in the most challenging strategic environment 
since the World War II. 


The Director General of the Australian Security Intelligence Organisation 
(ASIO) recently declared that Australia is facing an unprecedented challenge 
from foreign interference and espionage, and that he is not convinced that we 
fully appreciate the damage that it inflicts on our security, our democracy, our 
economy and our social fabric.' 


Because social media has become such a dominant form of communication it is 
also a dominant vector for foreign interference via disinformation, coordinated 
inauthentic behaviour networks and transnational repression, which carries 
profound consequences for our liberal democracy. 


Whether we like it or not, modern social media platforms are not just a mode of 
communication—in democratic states they have also become the new public 
square, where important issues are debated, interrogated and resolved. 
They help shape public opinion and, ultimately, the choices democracies make. 
For this reason they are a highly attractive domain for our potential adversaries, 


Mike Burgess Director-General of Security, Australian Security Intelligence Organisation, 
Director-General’s Annual Threat Assessment, 21 February 2023. 


143 


144 


8.7 


8.8 


8.9 


2 
3 


4 


who engage in information operations on these platforms to influence these 
decisions. 


Protecting people's rights to participate in our democracy in the digital town 
square is a balancing act. As the Australian Human Rights Commission (AHRC) 
raised with this committee, social media can be used for purposes that both 
strengthen or harm our democracy and values.? The difficult task for 
governments is to ensure any policy responses strike the right balance and 
protect the foundations of our democracy. All Australians must have their free 
speech protected while also preserving the fundamental right to participate in a 
democratic society that is free from covert influence and manipulation. 


This balancing act is even more precarious when the platform in question is 
headquartered in a country with a form of government that is fundamentally 
incompatible with our own. When asked why should a liberal democracy be 
uncomfortable with a platform like WeChat being the dominant source of 
information for a diaspora community if it is potentially controlled by a foreign 
government, Dr Seth Kaplan advised the committee that 'instead of your 
democracy being a debate among people who live in your country, there's an 
additional voice that plays a large part in the conversation, and that voice is 
controlled by a foreign government that does not have your best interests at 
heart ... that [is] the most clear danger'.* The committee heeds this warning, and 
believes we must take action now to shine a light on these covert, malign sources 
of influence in our democracy to make Australia a harder target for 
cyber-enabled foreign interference peddlers. 


Foreign interference does not only impact our public discourse. Many people 
living in Australia are not free of the long hand of their repressive former 
governments, reaching across the seas to continue to engage in acts of 
intimidation, harassment and violence including through social media. 
As Chinese-Australian artist and activist Badiucao testified to this committee, in 
relation to WeChat being used by the Chinese government for disinformation 
and propaganda purposes, we cannot allow a situation in which foreign 
authoritarian governments exploit social media platforms to export their 
censorship in a manner that is fundamentally at odds with our liberal 
democratic values and endangers our national security. Australia must protect 
those people, who deserve to live a life free from fear, and they deserve the 
protection of the Australian Government when malicious actors try to take away 
that freedom that all Australians enjoy. 


Australian Human Rights Commission, Submission 9, p. 3. 
Dr Seth Kaplan, Private capacity, Committee Hansard, 20 April 2023, p. 12-13. 


Committee Hansard, 21 April 2023, p. 35. 


145 


8.10 


8.11 


8.12 


8.13 


This is not a partisan issue. Liberal democracies around the world agree that 
foreign interference and information manipulation, particularly from 
authoritarian states, is one of the greatest contemporary challenges to 
democracy. 


As outlined by the AHRC, social media can be used to either strengthen or 
undermine democracy. Getting the settings right requires a clear-eyed, 
non-partisan approach to confront the dangers our nation faces via the 
weaponisation of social media to damage our democracy. 


We must also recognise the speed at which this challenge is moving as 
technology evolves exponentially. We can no longer afford to react only once 
the impacts of foreign interference become apparent, because at that point it is 
too late for countermeasures to be effective. We must learn to anticipate future 
risks to our democracy and social cohesion. 


That means our countermeasures must be agile and our regulatory framework 
adaptable to emerging technologies. Legislative settings must be platform and 
technology agnostic, based on the principles of safety and transparency with 
clear benchmarks for external oversight, and undergirded by meaningful 
sanctions when transparency principles are breached. 


Platform transparency 


8.14 


8.15 


8.16 


8.17 


Transparency is a foundational principle of any democracy. It is a key ingredient 
to build accountability and trust, and arguably the strongest antidote to 
disinformation in a system that seeks to preserve free speech. Australians must 
be able to trust that the information they see on social media platforms has not 
been manipulated to serve the strategic interests of a foreign government whose 
values and interests may run counter to our own. 


Democracy also relies on the polity being confident that accurate and truthful 
information is not being withheld through censorship, and that people are able 
to engage in free and frank discussion. However, the use of coordinated 
inauthentic behaviour (CIB) to distribute disinformation is neither free nor 
frank, as it leverages automatic processes— often coordinated from offshore—to 
amplify the voice of an interested party and create the illusion of support on a 
much larger scale. As one expert succinctly put it, why should a bot have the same 
free speech rights as me? 


The committee heard from numerous experts on cyber security, human rights, 
politics, and community cohesion, all of whom were consistent in their message 
that the lack of transparency about the way social media platforms operate 
creates a permissive environment for covert social manipulation that often goes 
undiscovered. 


Australia recognised the importance of transparency in strengthening our 
democracy via the introduction of the Foreign Influence Transparency Scheme 


146 


8.18 


8.19 


8.20 


8.21 


8.22 


8.23 


8.24 


(FITS) in 2018. The FITS requires foreign actors to register their lobbying and 
communications activities in Australia, and this scheme has since been 
replicated by other nations who have looked to us as a leader on these issues. 


Following a request from the Australian Government in 2020, the 
Digital Industry Group Inc (DIGI)—working in conjunction with industry — 
released the 2021 Australian Code of Practice on Disinformation and Misinformation 
(voluntary code), which committed a diverse set of technology companies to 
take steps to reduce the risk of online misinformation causing harm to 
Australians. Despite its admirable intent, there is little evidence to suggest the 
voluntary code has been effective in combating foreign state disinformation, 
which remains rife on both western-headquartered social media platforms and 
those from authoritarian states. 


The Australian Government has released an exposure draft of the 
Communications Legislation Amendment (Combatting Misinformation and 
Disinformation) Bill 2023 (the Bill), which gives the Australian Communications 
and Media Authority (ACMA) powers to gather information from platforms on 
their records regarding misinformation and disinformation; request industry 
develops a code of practice; and allows the ACMA to create and enforce 
industry standards should the code be deemed ineffective. 


Although the draft bill was raised during public hearings of the 
Select Committee, we did not conduct a formal inquiry into the bill. For that 
reason, it would not be appropriate for the committee to express a view about 
the merits or otherwise of the Australian Government's proposed approach. 


Regardless of whether the draft bill proceeds or not, the committee believes that 
the increasing risk that foreign interference and disinformation poses to 
Australia's democratic institutions, values and way of life, means that there is a 
pressing need for additional action to counter the efforts of authoritarian states 
that seek to weaponise social media platforms against liberal democracies like 
Australia. 


The committee agrees with evidence that censorship and the reporting of 
alleged misinformation can itself present a risk of foreign interference. 


The AHRC noted ‘increased examples of extra-territorial censorship, where 
governments seek to suppress speech outside of their national borders’. 
ASIO advised that acts such as these 'could become foreign interference if they 
involve the hidden hand of a foreign state’. 


Foreign government officials pressuring social media companies to make 
censorship content removal decisions which are in their political or strategic 


5 Australian Human Rights Commission, Submission 9, pp. 4 and 15. 


147 


8.25 


8.26 


8.27 


8.28 


8.29 


8.30 


8.31 


interests but contrary to Australia's democratic processes and national interests 
represents a foreign interference risk. 


While some platforms do report formal legal requests made by government and 
any action taken as a result, is the removal or restriction of content after informal 
or non-official requests from foreign government officials, particularly where it 
is later claimed by the platform that the content breached their policies, that is 
particularly lacking in transparency. As acknowledged by Twitter, this type of 
action reduces public trust. 


Additionally, though, if content removal, restriction or visibility filtering occurs 
after an informal request from a foreign government which is not disclosed by 
platforms, this can result in an unacceptable form of foreign interference in 
Australian public debate and discussion. 


Decisions made by social media companies to censor or remove content on the 
grounds that it is allegedly ‘misinformation’ or causes ‘harm’ can adversely 
affect public discourse in our democracy. This was particularly demonstrated 
by Meta's decisions during the pandemic to restrict content on its platform 
discussing the theory that a laboratory accident might have been involve in the 
origins of the virus as 'misinformation’, despite the fact that we now know that 
the US Intelligence Community was asked by the Biden administration to 
investigate the origins of the virus and are divided in their findings on this issue. 
The Australian public had no visibility over how such decisions were made and 
whether there was pressure from foreign governments to remove such content, 
and this demonstrates that less censorship, rather than more, is the safest option 
for our democracy. 


Current transparency measures by social media companies do not adequately 
cover pressure applied by government officials to censor content where this 
pressure is applied outside of formal legal channels. 


There is wide scope for foreign government officials to pressure social media 
staff to make a finding that content that they wish to have removed should be 
interpreted as being in breach of the platform's rules, despite not having been 
deemed to be so prior to the government's request. 


This issue goes directly to the concerns about censorship raised by submitters 
and witnesses that social media platforms should be required to be fully 
transparent about the content they censor or visibility filter in response to 
requests from foreign governments, whether as a result of a legal process or 
through other channels. 


Under current policies, decisions to censor content following requests from 
foreign governments can be obscured by statements from platforms that the 
content breached their content policies. 


148 


8.32 


8.33 


8.34 


8.35 


8.36 


8.37 


8.38 


8.39 


There is currently an unacceptable risk of staff at social media companies 
making content moderation decisions which affect Australian political 
discourse and democratic processes under pressure from foreign government 
officials, without this being adequately disclosed to the Australian public. 


Several experts who testified before the committee recommended that the best 
path forward is to introduce enforceable transparency obligations that social 
media companies must meet to continue operating in Australia. 


Dr Seth Kaplan recommended a 'step-by-step approach’ where we say ‘these are 
the rules that function in a democracy, these are the things we expect and these 
are the penalties' and serious non-compliance could be met with enforcement 
measures, including up to a ban of the social media application.° 


Mr Albert Zhang from the Australian Strategic Policy Institute also favoured 
‘regulation or at least a discussion about how we standardise and create better 
reporting mechanisms to increase transparency’, and Mr Fergus Ryan called for 
‘legislation that deals with any other emerging apps that may come out of 
countries like China’.” 


Similarly, Australian cybersecurity firm CyberCX called for ‘mandatory 
compliance and report frameworks for social media platforms' so that the 
government has the final say on managing risks to our democracy.® 


Finally, the AHRC supported establishing ‘clear and mandatory requirements, 
and pathways, for social media organisations to report suspected foreign 
interference’ and to require social media platforms to publicly disclose the 
content that they censor and make it an offence to censor content where that has 
not been publicly disclosed to users.’ 


Given this, the committee recommends an approach that favours transparency 
over censorship, whereby platforms are given reasonable hurdles to meet and it 
is incumbent on them to take reasonable steps to inform Australians about the 
origin, and, where possible, the intent of the content they are exposed to so they 
can make up their own minds about its merits. This serves as a reasonable 
alternative to a more heavy-handed approach, wherein decisions about what 
constitutes allowable speech are outsourced to tech platforms—most of which 
are headquartered overseas—in the name of user ‘protection’. 


For example, content which has been published by a proxy of an authoritarian 
state, such as state media broadcasters like Russia's RT, or China's Xinhua, 


6 Dr Seth Kaplan, Private capacity, Committee Hansard, 20 April 2023, p. 16. 


Mr Fergus Ryan, Analyst, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, 


p. 21 


8 CyberCX, Submission 16, p. 4. 


Australian Human Rights Commission, Submission 9, p. 9. 


149 


8.40 


8.41 


8.42 


would be labelled as such, instead of being censored. Informed of the origins of 
this content, users can decide for themselves how much weight to award it. 
Some social media platforms already do this, while others have never done so, 
or recently ceased doing so. 


However, transparency should not be restricted to information that users see, it 
must also be for information that users do not see due to censorship or other 
forms of visibility manipulation. Australian laws should discourage censorship 
of political discussion and public policy debate by social media platforms 
outside of very clearly defined legal processes. 


Under this transparency-led model, platforms who fail to meet these reasonable 
standards would be fined, while repeated non-compliance could result in a ban 
given the harmful impact this conduct would have on our democracy. 


The committee therefore recommends the Australian Government immediately 
create a system of enforceable minimum transparency standards that all social 
media platforms operating in Australia must meet, underpinned by appropriate 
sanctions to ensure compliance up to and including banning platforms from 
operating within Australia. 


Recommendation 1 


8.43 


8.44 


The committee recommends the Australian Government require all large 
social media platforms operating in Australia to meet a minimum set of 
transparency requirements, enforceable with fines. Any platform which 
repeatedly fails to meet the transparency requirements could, as a last resort, 
be banned by the Minister for Home Affairs via a disallowable instrument, 
which must be reviewed by the Parliamentary Joint Committee on 
Intelligence and Security. 


Requirements should include, at minimum, that all large social media 
platforms: 


e must have an Australian presence; 

e must proactively label state affiliated media; 

e must be transparent about any content they censor or account takedowns 
on their platform; 

e must disclose any government directions they receive about content on 
their platform, subject to national security considerations; 

e must disclose cyber-enabled foreign interference activity, including 
transnational repression and surveillance originating from foreign 
authoritarian governments; 

e must disclose any takedowns of coordinated inauthentic behaviour (CIB) 
networks, and report how and when the platform identified those CIB 
networks; 


150 


e must disclose any instances where a platform removes or takes adverse 
action against an elected official's account; 

e must disclose any changes to their platform's data collection practices or 
security protection policies as soon as reasonably practicable; 

e must make their platform open to independent cyber analysts and 
researchers to examine cyber-enabled foreign interference activities; 

e must disclose which countries they have employees operating in who 
could access Australian data and keeps auditable logs of any instance of 
Australian data being transmitted, stored or accessed offshore; and 

e must maintain a public library of advertisements on their platform. 


Platforms headquartered in authoritarian states 


8.45 


8.46 


8.47 


Experts in cyber security and foreign interference sent a clear and consistent 
message to the committee: social media platforms that originate from 
authoritarian states present an additional layer of risk. CyberCX warned the 
committee that the collection and aggregation of the personal information of 
millions of Australians and the capacity for malign foreign actors to manipulate 
content consumed by Australians at scale is a heightened risk for platforms that 
are linked to authoritarian governments, including TikTok and WeChat.!? As 
they pointed out, Chinese government authorities operate ‘without the 
oversight and transparency mechanisms of rule-of-law democracies’, and 
therefore it is clear to the committee that platforms headquartered in 
authoritarian states deserve even greater scrutiny because of the heightened 
risks to our democracy and citizens. 


It is not merely that authoritarian states tend to place less emphasis on personal 
privacy and data protection. It is that those authoritarian states have 
deliberately — themselves or by proxy—designed social media platforms that 
can both obscurely harvest vast swathes of user data while also covertly 
manipulating the information environment to serve the interests of the 
intervening state. Dr William Stoltz from the Australian National University's 
National Security College advised this committee that information campaigns 
can be weaponised to 'flood the information sphere’ with multiple and even 
contradictory narratives that sow confusion or discord, distract attention, and 
to encourage the target audience to question the authenticity of other 
information and induce wider cynicism." 


ASIO highlighted the additional security concerns that authoritarian 
governments ‘are able to direct their country's institutions—including media, 


10 CyberCXx, Submission 16, p. 5. 


1 Dr William Stoltz, National Security College, Australian National University, Submission 18, p. 9. 


151 


businesses and society —to support intelligence or foreign policy objectives in 
ways which are not acceptable in a democracy’. 


8.48 The committee is alarmed by this rising authoritarianism creeping into our 
society through the digital domain, and we must be alert and ready to respond 
to these grey zone tactics that fall short of war but still corrode our democracy 
and sovereignty. 


8.49 These platforms’ ability to gain and maintain our attention through opaque 
algorithms and relentlessly collect user data did not develop by accident. 
Each platform's commitment to these features goes well beyond a simple 
commercial imperative as failure to comply with the will of an authoritarian 
government is often an existential decision for platforms headquartered in these 
countries. Consequently, these tactics are vigorously defended by both the 
platforms themselves as well as their authoritarian governments who have a 
vested interest in preserving access to harvested data from democratic nations. 
It is little wonder that China's Ambassador to Australia, Xiao Qian, protested 
the Australian Government's decision on 4 April 2023 to ban TikTok from 
government-owned devices and cease using technology from 
Chinese-manufactured companies which are ultimately beholden to the 
demands of the Chinese Communist Party (CCP). 


8.50 The committee's concerns are echoed across the globe. As early as 2015, the 
European Council publicly stressed 'the need to challenge Russia's ongoing 
disinformation campaigns’ and called for ‘an action plan on strategic 
communication’. A recent joint address by the heads of Security Service MI5 
(United Kingdom) and the Federal Bureau of Investigation (United States) noted 
that the CCP is covertly applying pressure across the globe via a coordinated 
campaign on a grand scale that involves planned, professional activity in 
support of a decades-long strategic contest. !5 


8.51 In the case of TikTok and WeChat, both platforms originate from China, where 
national security laws such as Article 7 of the National Intelligence Law of 2017 
require those platforms, and their employees, to assist national security agencies 
with any request they may make, and furthermore, to keep those requests secret. 
As Ms Shanthi Kalathil testified to this committee, 'were the [Chinese] state to 
go to [ByteDance and Tencent] with certain demands, they would be unable to 


Australian Security Intelligence Organisation, Submission 2, p. 4. 


Karen Barlow, ‘China 's ambassador to Australia slams speculation of TikTok, surveillance device 
spying ', Canberra Times, 18 May 2023. 


4 European Council conclusions, 20 March 2015, EUCO 11/15, p. 5. 


5 Security Service MI5, Joint Address by MI5 and FBI Heads, 6 July 2022, 
www.mid.gov.uk/news/speech-by-mi5-and-fbi (accessed 14 July 2023). 


152 


8.52 


8.53 


8.54 


legally or in any other capacity resist those demands'.'* The committee is deeply 
concerned that the consequence of this extrajudicial direction is that social 
media companies that are ultimately beholden to the CCP have unfettered 
access to the personal data of millions of Australians that could ultimately end 
up in the hands of a foreign intelligence service. 


Throughout this inquiry, both WeChat and TikTok have been reluctant 
participants in this parliamentary scrutiny of social media platforms—a scrutiny 
that is itself an expression of Australia's democracy. This reluctance to 
participate speaks volumes about the respect those platforms hold for 
Australian democratic processes, and stood in stark contrast to the more 
cooperative disposition of platforms headquartered in western countries who 
recognise the fundamental importance of the checks and balances inherent in 
democratic systems. 


The committee notes that WeChat repeatedly declined multiple invitations to 
participate in a public hearing on grounds it does not have a legal presence in 
Australia, ignoring that the invitation allowed them to participate via 
videoconference from any location in the world—an option other witnesses 
utilised. As Chair of the Select Committee, Senator Paterson sent an open letter 
on 4 July 2023 to WeChat urging them to reconsider their refusal to appear at a 
public hearing. While WeChat reiterated its stated intention to ‘working 
collaboratively with Australian regulators and authorities’ and said that it 
remained ‘committed to providing responsive information to the committee in 
writing’, its blanket refusal to front up in an open forum demonstrates to the 
Australian public that WeChat is not genuinely committed to being held 
accountable for the allegations of censorship, surveillance and foreign 
interference at the hands of the CCP that are rife on its platform.” WeChat's 
written responses, delivered on 26 July 2023, to the committee's 53 questions on 
notice, do nothing to assuage our strongly held concerns. WeChat's responses 
demonstrate a non-genuine effort to assist the committee with answers that 
completely lack credibility and are widely contradicted by the evidence of 
independent experts. 


TikTok was similarly reluctant to participate, requiring the committee to remind 
them of its powers to compel any Australian-based employee to appear at a 
hearing. Once in attendance, the committee found TikTok engaged in a 
determined effort to obfuscate and avoid answering simple questions about 
their platform's operations and its links to their parent company, ByteDance, 
and its relationship with the CCP. 


16 Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 3. 


17 Senator James Paterson, 11 July 2023, https://twitter.com/SenPaterson/status/1678557229883207681 
(accessed 29 July 2023). 


153 


8.55 On all the available evidence, including TikTok's admission that the majority of 


ByteDance employees are based in China, the committee does not accept 
TikTok's statement that 'ByteDance operates as a global company without an 
officially designated headquarters.' This claim has been contradicted by TikTok 
and ByteDance's own public statements including in court-filings in the US.'8 
It is clear that TikTok's parent company, ByteDance, is headquartered in China 
where the majority of its employees are based, and is therefore subject to the 
Chinese Government's laws including the 2017 National Intelligence Law. As 
TikTok witnesses reluctantly admitted, those China-based employees can 
remotely access Australian user data, and can even make changes to the 
algorithm. 


8.56 TikTok's obfuscation continued with their responses to questions on notice, 


which were not appropriately answered. TikTok told the committee that ‘data is 
protected, kept and logged in our company'” but were unable to give a number 
on how often Australian user data had been accessed by employees in China, 
and TikTok said it did not have specific numbers but would take that on notice. 
TikTok's follow-up answer was not enlightening either; TikTok failed to 
quantify the number of times Australian user data had been accessed by 
mainland China. The only reasonable conclusions the committee can reach is 
that TikTok does not track and log this data access in the way it first suggested 
to the committee and has failed to correct the record, or it does do so but is 
refusing to provide the information because it would be a shockingly large 
number. Neither prospect reflects well on the company, its officers or its 
commitment to comply with Australian law. 


8.57 Again, this is not an issue that is isolated to Australia. Other nations have sought 


18 


to engage with TikTok about ongoing security concerns they hold with the 
practices of the platform, and have also found TikTok to be reluctant 
participants who were evasive and misleading under questioning. In their letter 
to the US Federal Trade Commission, US senators Mark R. Warner (D-VA) and 
Marco Rubio (R-FL) criticised the ‘repeated misrepresentations by TikTok 


John Garnaut et al, Submission 34, p. 39 citing TikTok Inc v Donald J Trump, Plaintiffs ' Notice of 
Filing, 10 November 2010: 'The parties [TikTok Inc and ByteDance Ltd] did not submit the 
Musically transaction to CFIUS for review in 2017 because ByteDance was a 
Chinese-headquartered company and Musical.ly was also a Chinese-headquartered company’, p. 
12. www.scribd.com/document/483797602/TikTok-asks-U-S-federal-appeals-court-to-vacate-U-S- 
divestment-order#. 


Ms Ella Woods-Joyce, Acting Director of Public Policy, Australia and New Zealand, and 
Mr Will Farrell, Security Officer, TikTok US Data Security, TikTok, Committee Hansard, 11 July 2023, 
pp. 23-24. 


154 


8.58 


8.59 


8.60 


concerning its data security, data processing, and corporate governance 
practices'.”° 


It is also telling that all social media platforms who appeared before the 
committee stated that they found and removed CIB that sought to influence 
Australia. In contrast, TikTok declared that there was no such CIB on its 
platform.” The committee holds this declaration in high suspicion. 


Concerningly, in answers to questions on notice, TikTok Australia admitted that 
its much-vaunted Project Texas, designed to supposedly protect American user 
data, and Project Clover, which purports to protect European user data, has no 
Australian equivalent. Although widely criticised by independent experts— 
including Ms Shanthi Kalathil? and the US Federal Communications 
Commissioner Mr Brendan Carr» who testified before this committee—as 
insufficient to protect user data, TikTok in these jurisdictions at least feels 
compelled to offer this fig-leaf. It is telling that no similar proposal exists for 
Australian users. Australia cannot again be left behind, and must be included in 
any solution to the problem posed by ByteDance's ownership of the app. 


The committee notes the ongoing exploration of options in relation to ownership 
of TikTok in the US, which are centered on divesting ownership away from a 
company that is beholden to the national security laws of the CCP, thereby 
severing TikTok's obligations to cooperate with China's intelligence apparatus. 
Should the US Government take action to force Bytedance to divest ownership 
of TikTok, the Australian Government should take advantage of that move to 
implement similar requirements in Australia. 


Recommendation 2 


8.61 


The committee recommends that, should the United States Government force 
ByteDance to divest its stake in TikTok, the Australian Government review 
this arrangement and consider the appropriateness of ensuring TikTok 
Australia is also separated from its ByteDance parent company. 


Apps on government devices 


8.62 


On 4 April 2023, the Australian Government issued a directive under the 
Protective Security Policy Framework (PSPF) that TikTok could not be installed on 
any Australian Government-issued devices due to the serious espionage risk. 


2 Senator Mark R. Warner (US), 'Warner, Rubio call for Investigation into TikTok in Light of 
Revelations about Chinese Communist Party 's Potential Access to U.S. Data’, 5 July 2022. 


21 Ms Ella Woods-Joyce, TikTok, Committee Hansard, 11 July 2023, p. 20. 


22 Ms Shanthi Kalathil, Private capacity, Committee Hansard, 20 April 2023, p. 4. 


233 Mr Brendan Carr, Commissioner, US Federal Communications Commission, Committee Hansard, 
20 April 2023, pp. 10-11. 


155 


8.63 Ms Abigail Bradshaw, the Deputy Director General of the Australian Signals 
Directorate and Head of the Australian Cyber Security Centre, outlined the 
rationale for the ban in compelling evidence to the committee. Ms Bradshaw 
detailed the extensive data collection practices of TikTok, including its attempts 
to access data held by other applications on a device, and noted the company 
was subject to the extrajudicial direction of the Chinese Government. When 
asked about TikTok's public statements that it has never been asked to hand 
over its data to the Chinese Government, Ms Bradshaw advised that she had 
‘not seen technical controls that would provide a basis for technical advice that 
the risks of sharing data are adequately mitigated’. 


8.64 While the ban of TikTok from Australian Government devices is a promising 
first step, there are still security gaps that must be addressed. For example, the 
Attorney-General's Department (AGD) noted that while the PSPF also applied 
to government contractors, AGD did not have oversight over whether 
departments had turned their minds to ensuring contractors either knew about 
or were adhering to the TikTok ban. If TikTok is not safe to be on the device of 
a government employee, it is not safe to be on the device of a government 
contractor who has access to similarly sensitive information. 


8.65 During the inquiry it emerged that several major consulting firms took the 
decision to ban TikTok from their employee's work-issued devices following 
correspondence from the Shadow Minister for Home Affairs and 
Cyber Security.” 


8.66 WeChat poses a similar data security risk to TikTok and should be added to the 
PSPF ban, with appropriate exemptions available on a case-by-case basis 
provided sufficient security mitigations are deployed, as is the case with TikTok. 
Additional research on other platforms should be undertaken, with a view to 
developing more detailed guidance on the installation of any similar social 
media platforms onto devices that can access sensitive government data and 
information. 


8.67 Critical infrastructure entities regulated under the Security of Critical 
Infrastructure Act 2018 (SOCI Act) especially those designated as Systems of 
National Significance by the Minister for Home Affairs, are recognised as 
providers of essential services to the Australian people. Under the SOCI Act, 
entities are required to take steps to protect themselves from a range of risks, 
including risks to cyber security. Evidence provided by the Department of 
Home Affairs (Home Affairs) during Senate Estimates indicated it was an option 


24 Ms Abigail Bradshaw, Deputy Director-General, Australian Signals Directorate, Committee Hansard, 
12 July 2023, p. 3. 


23 Senator James Paterson, Committee Chair, and Ms Sarah Chidgey, Deputy Secretary, National 
Security and Criminal Justice, Attorney-General's Department Committee Hansard, 12 July 2023, 
pp. 20-21. 


156 


8.68 


available to the government to direct these entities to take reasonable steps to 
mitigate the risk of apps like TikTok.” 


Applications like TikTok and WeChat illustrate the broader risk to sensitive 
government information from software and hardware posed by high-risk 
vendors, particularly those subject to the control of authoritarian foreign 
governments. It was clear during the inquiry that there is currently no entity 
within government with central policy responsibility for mapping, assessing 
and mitigating the risks posed by these vendors. Too often, government is 
reactive in its approach to high-risk technologies, only taking action to ban 
software or restrict hardware after it has generated public controversy. We need 
to move to a proactive setting which considers the risk of emerging technologies 
before they are widely installed by government users and subsequently have to 
be removed or have mitigations applied at great cost and inconvenience. 


Recommendation 3 


8.69 


8.70 


The committee recommends the Australian Government extend, via policy or 
appropriate legislation, directives issued under the Protective Security Policy 
Framework regarding the banning of specific applications (e.g. TikTok) on all 
government contractors’ devices who have access to Australian government 
data; and 


The Minister for Home Affairs should review the application of the 
Security of Critical Infrastructure Act 2018, to allow applications banned 
under the Protective Security Policy Framework to be banned on work-issued 
devices of entities designated of Systems of National Significance. 


Recommendation 4 


8.71 


The committee recommends the Australian Government consider extending 
the Protective Security Policy Framework directive banning TikTok on 
federal government devices to WeChat, given it poses similar data security 
and foreign interference risks. 


Recommendation 5 


8.72 


The committee recommends the Australian Government continues to audit 
the security risks posed by the use of all other social media platforms on 
government-issued devices within the Australian Public Service, and issue 
general guidance regarding device security, and if necessary, further 
directions under the Protective Security Policy Framework. 


2% Mr Michael Pezzullo AO, Secretary, and Mr Hamish Hansford, Deputy Secretary, Cyber and 


Infrastructure Security Centre, Department of Home Affairs, Senate Legal and Constitutional 
Affairs Legislation Committee, Estimates Committee Hansard, 22 May 2023, pp. 67-68. 


Recommendation 6 


8.73 


The committee recommends the Australian Government establish a national 
security technology office within the Department of Home Affairs to map 
existing exposure to high-risk vendors such as TikTok, WeChat and any 
similar apps that might emerge in the future. It should recommend 
mitigations to address the risks of installing these applications, and where 
necessary, ban them from being installed on government devices. 


Building the capacity of government 


Lead agency 


8.74 


8.75 


8.76 


8.77 


8.78 


The committee considers that the Australian Government must urgently 
increase its expertise and technical capability in combatting foreign interference 
through social media to address current and emerging threats. 


In this report, the committee has mapped the departments, agencies and 
taskforces involved in addressing foreign interference through social media and 
created a visual diagram showing the complexity and diffusion of responsibility 
created by these arrangements. This was further highlighted in discussions with 
Home Affairs, who told the committee that despite having responsibility to run 
the Counter Foreign Interference Coordination Centre, it was not a member of 
the Counter Foreign Interference Taskforce.” 


While a range of agencies contribute their specialist knowledge to track, analyse 
and counter foreign interference, there is a general lack of accountability because 
no single entity is accountable for the outcomes. A dedicated body is needed to 
coordinate government efforts and serve as a one-stop shop for individuals and 
private sector stakeholders to report and seek advice about suspected foreign 
interference through social media. This body should also serve a public outreach 
function and regularly publish advice to support companies and individual 
recognise and appropriately respond to foreign interference activity. 


The AHRC, the Australian Strategic Policy Institute and CyberCxX all testified to 
this committee that the Australian Government should nominate a lead 
government entity that is responsible for countering cyber-enabled foreign 
interference.” 


The committee notes that this proposed body, and existing agency efforts, need 
to be adequately resourced. Despite an announcement on 14 February this year 
that Home Affairs and ASIO have been tasked with a new community outreach 


27 Ms Sally Pfeiffer, Acting First Assistant Secretary, Counter Foreign Interference, Department of 
Home Affairs, Committee Hansard, 12 July 2023, p. 12. 


2 Australian Human Rights Commission, Submission 9, p. 8; CyberCX, Submission 16, p. 4; 
Mr Albert Zhang, Analyst, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, 
p. 21. 


158 


program to counter foreign interference, Home Affairs informed the committee 
it was not given any new resources to undertake this work. It is vital that 
Australia's frontline agencies in the fight against foreign interference are 
adequately resourced so that the acquittal of their broader functions is not 
weakened or jeopardised due to resources being spread too thin. 


8.79 The committee further notes the recent agreement between the European Union 
and the US to use a common methodology for identifying, analysing and 
countering foreign interference. By using the DISARM framework, STIX2 
standard and the OpenCTI platform, information between the two regions will 
be shared more efficiently, effectively and with a greater level of detail. A lead 
agency in Australia should quickly move to adopt the same standards and join 
this coalition so that we can leverage the learnings and scale of likeminded 
partners while sharing our own experiences to inform best practice. 


Recommendation 7 


8.80 The committee recommends the Australian Government designate an entity 
with lead responsibility for whole-of-government efforts to counter 
cyber-enabled foreign interference, with appropriate interdepartmental 
support and collaboration, resources, authorities and a strong public outreach 
mandate. 


Cyber security strategy should include foreign interference 

8.81 Home Affairs is currently developing the 2023-2030 Australian Cyber Security 
Strategy. Earlier this year Home Affairs published a discussion paper seeking 
views to inform the final strategy, however despite the discussion paper noting 
that cyber technology provides a conduit for ‘crime, foreign interference, 
espionage, disinformation and misinformation’, none of these issues are 
addressed in the suggested 'core policy areas that the Expert Advisory Board 
expects will be addressed in the Strategy'.”? The committee is concerned that this 
area of risk is not being appropriately addressed within the strategy, which 
provides a logical mechanism to address the risk of cyber-enabled foreign 
interference as part of broader efforts to uplift Australia's national cyber 
resilience. 


Recommendation 8 

8.82 The committee recommends the Australian Government address countering 
cyber-enabled foreign interference as part of the 2023-2030 Australian Cyber 
Security Strategy. 


29 


Australian Government, 2023-2030 Australian Cyber Security Strategy: Discussion Paper, pp. 6 and 16. 


159 


Magnitsky sanctions 


8.83 


8.84 


There are existing provisions within the Autonomous Sanctions Act 2011 which 
allow the Australian Government to impose targeted financial sanctions and 
travel bans against perpetrators and beneficiaries of prohibited behaviours and 
actions. The scheme allows the government to create sanctions that are either 
country-specific or thematic. Thematic sanctions can currently be imposed for: 
... the proliferation of weapon of mass destruction; threats to international 
peace and security; malicious cyber activity; serious violations or serious 
abuses of human rights; activities undermining good governance or the rule 


of law, including serious corruption; and serious violations of international 
humanitarian law.°? 


The committee recommends that the scope of the Australia's Autonomous 
Sanctions regime should be clarified to ensure include foreign interference 
through social media, via amendments to the Act if necessary. This will serve as 
a deterrent to foreign states seeking to conduct foreign interference in Australia, 
and will allow Australia to issue sanctions and attributions in concert with 
likeminded partners for foreign interference attempts as we already have the 
ability to do for cyber-attacks. 


Recommendation 9 


8.85 


The committee recommends the Australian Government clarify that 
Magnitsky-style cyber sanctions in the Autonomous Sanctions Act 2011 can be 
used to target cyber-enabled foreign interference actors, via legislative 
amendment if necessary, and ensure it has appropriate, trusted frameworks 
for public attribution. 


Capacity to lay charges for foreign interference 


8.86 


8.87 


The committee heard from a range of community groups about the impacts that 
foreign interference has on the lives of many culturally diverse people in 
Australia. These groups and individuals make numerous reports to the 
National Security Hotline on specific instances of interference, threats, harm and 
campaigns of harassment, many of which are conducted using social media 
platforms. 


Despite these numerous reports, the Australian Federal Police (AFP) reported 
to the committee that not a single person has been charged with offences relating 
to foreign interference via a social media platform under the National Security 
Legislation Amendment (Espionage and Foreign Interference) Act 2018 
(the Espionage Act). The AFP noted there is a very high bar to laying such 
charges, which requires either a foreign principal or a proxy of a foreign 


30 Department of Foreign Affairs and Trade, Autonomous Sanctions Amendment (Magnitsky-style and 
Other Thematic Sanctions) Act 2021, Www.dfat.gov.au/news/news/autonomous-sanctions- 


amendment-magnitsky-style-and-other-thematic-sanctions-act-2021 (accessed 24 July 2023). 


160 


8.88 


8.89 


principal to be undertaking the action. As such, the Espionage Act should be 
reviewed to ensure the settings are correct for the current operating 
environment. 


Further, the Law Council of Australia (Law Council) submitted that the 
intention was for offences introduced by the Espionage Act into the 
Criminal Code Act 1995 to be applied to conduct where social media is used to 
exert the influence on behalf of a foreign actor by deceptive or covert means. 
However, the Law Council queried the utility of these provisions being used 
against instances of foreign interference through social media given 'the 
challenges that exist in relation to successfully investigating and prosecuting 
persons who commit this offence when the 'conduct' occurs outside Australia’.*! 


The Parliamentary Joint Committee on Intelligence and Security (PJCIS) is 
currently reviewing the Foreign Influence Transparency Scheme. Despite evidence 
put to the committee that these reforms should be considered as part of a 
package with the Espionage and Foreign Interference Act 2018, the PJCIS is not 
required to complete a review of the Espionage Act, and has not been referred 
an inquiry to do so. The scheduled review of the Espionage Act by the 
Independent National Security Legislation Monitor (INSLM) is not likely to be 
completed in this term of the INSLM due to other review priorities. 


Recommendation 10 


8.90 


The committee recommends the Australian Government refer the 
National Security Legislation Amendment (Espionage and Foreign Interference) 
Act 2018 to the Parliamentary Joint Committee on Intelligence and Security 
for review, with particular reference to the Act's effectiveness in addressing 
cyber-enabled foreign interference. 


Artificial intelligence: an emerging threat 


8.91 


8.92 


31 


The committee is alarmed at the increasing national security risks associated 
with the potential weaponisation of artificial intelligence (AI) technologies by 
malicious actors. These concerns have sharply increased with the advent of 
generative AI tools such as ChatGPT and Midjourney, which can be used to 
generate content at a speed and scale we have never seen before. 


Expert witnesses told the committee that AI will exponentially increase the 
volume of disinformation and foreign agents engaging in CIB. 
Mr David Robinson from Internet 2.0 warned the committee that 'because of 
artificial intelligence we assess time is not on our side’ and that AI is 'increasing 
the effectiveness of influence and disinformation campaigns against elections’, 


Law Council of Australia, Submission 27, pp. 2-3. 


161 


8.93 


cautioning that we may not be able to reverse the loss of trust our system will 
suffer. 


The Department of Industry, Science and Resources is currently leading the 
Australian Government's public consultation on the responsible use of AI. The 
Government's discussion paper on 'safe and responsible AI in Australia’ 
specifically excludes consideration of the national security implications of AI. 
This is one of the most pressing areas of concern today. The Australian 
Government must urgently address the national security implications in our 
policy response to AI. 


Recommendation 11 


8.94 


The committee recommends the Australian Government investigate options 
to identify, prevent and disrupt artificial intelligence (AI)-generated 
disinformation and foreign interference campaigns, in addition to the 
Government's Safe and Responsible AI in Australia consultation process. 


Intelligence briefings 


8.95 


8.96 


The committee heard from both social media platforms and government 
agencies about the importance of collaborative relationships between the two 
sectors. However, cooperative platforms were often stymied in their ability to 
take targeted action because they lack the threat intelligence that could assist 
them in focusing their search for disinformation and foreign-state coordinated 
inauthentic behaviour. 


One of the stated barriers to greater threat intelligence sharing is the limited 
number of security-vetted staff working for social media platforms. Noting that 
there are some platforms with which it would be inappropriate to share any 
classified material, providing a greater degree of threat intelligence with 
appropriately vetted staff at trusted platforms would assist those platforms in 
streamlining efforts to counter foreign interference through social media. 


Recommendation 12 


8.97 


The committee recommends the Australian Government establish a program 
of vetting appropriate personnel in trusted social media platforms with 
relevant clearances to ensure there is a point of contact who can receive threat 
intelligence briefings. 


32 Mr David Robinson, Director, Internet 2.0, Committee Hansard, 20 April 2023, p. 31 


33 


Department of Industry, Science and Resources, Safe and responsible AI in Australia: Discussion Paper, 


June 2023, p. 4. 


162 


Building the capacity of civil society 


8.98 


8.99 


The committee heard that Australians lack the information, expertise and 
resources to understand the risks presented by the use social media platforms 
and the information they engage with online. 


Given the declining trust in democratic institutions and leaders, the increasing 
polarisation of opinion in society and the dominant role of social media 
platforms in our contested information environment, it is clear from the 
evidence received over the course of this inquiry that a coordinated national 
approach is required. While government and industry have a significant role to 
play, efforts to counter foreign interference and CIB through social media must 
include civil society. 


8.100 The ability of civil society—individuals, organisations and community 


groups—to make informed decisions about information consumption and 
sharing needs to be expanded. To address the threat of foreign interference 
through social media, government support and funding is required to build this 
capacity. 


Improving independent research and frameworks 


8.101 The committee considered evidence supporting the role of expert centres and 


researchers — whether engaged by platforms or operating independently in civil 
society —to scrutinise the conduct of the platforms and those who seek to 
manipulate them for their own ends. These independent experts help people 
understand how social media platforms use and distribute data and content that 
is capable of shifting public opinion, including through personal data collection 
and use of algorithms which promote and filter content. Independent experts 
can also help highlight where these algorithms are being used maliciously or in 
an inauthentic manner to covertly sway public opinion or create chaos. 


8.102 However, the committee is very aware that the effectiveness of independent 


research will be largely determined by the transparency of social media 
platforms as discussed in Recommendations 1 and 2—including in relation to 
their data collection policies, algorithms, and open access to social media 
platforms. 


8.103 When provided access to relevant data, the committee has heard that expert 


centres and researchers can play a vital role in understanding how social media 
platforms operate, the effectiveness of foreign actors’ content operations, and 
the nature and scale of certain cybersecurity threats.** Support from the 
Australian Government would ensure that cyber-enabled foreign interference 


34 See, for example: Department of Home Affairs, Submission 1, p. 3; University of Adelaide, 
Submission 3; US Federal Communications Commission, Submission 4, p. 2; RAND Australia, 
Submission 11, p. 3. 


163 


activities or campaigns in Australia could be more consistently and capably 
monitored and publicly reported.* 


8.104 This support could take the form of grant funding for social media monitoring 
and investigations, bolstering laws ensuring researchers can access more and 
higher-quality information data.* 


8.105 The committee also acknowledges the vital work that independent 
organisations undertake in exposing and analysing foreign interference. Expert 
Mr David Robinson told the committee that, in one instance, social media 
companies investigating commentary on their platforms after a particular event 
declared them to be free of interference. However, when using a mathematical 
analysis, Mr Robinson and other cybersecurity experts identified an interference 
campaign.” 


8.106 This example demonstrates that even when looking closely, sometimes even the 
platforms themselves cannot discern bots from people or campaigns of influence 
from genuine free expression. It requires the expertise of specialist organisations 
to review available data so that all of society can map an accurate picture of 
foreign interference. Some companies are more transparent than others when it 
comes to making data available for this kind of review due to commercial 
incentives, risk avoidance or other reasons. As such, Recommendations 1 and 2 
will complement research efforts by ensuring platforms open themselves to 
independent cyber analysts and researchers to examine cyber-enabled foreign 
interference activities, but the Australian Government also needs to ensure 
independent researchers are supported to make the most of the opportunities 
this data provides. 


Recommendation 13 

8.107 The committee recommends the Australian Government build capacity to 
counter social media interference campaigns by supporting independent 
research. 


Protecting the public and diaspora communities 

8.108 As technology continues to evolve, it is important that all elements of Australian 
society — government, business, civil society, and individuals—be equipped to 
respond appropriately to the threat of foreign interference and disinformation. 


8.109 In addition to the recommendations above aimed at improving the integrity and 
transparency of all social media platforms operating in Australia, it is vital that 
the Australian Government lead an integrated whole-of-nation approach. 


35 CyberCX, Submission 16, p. 9. 
36 ASPI, Submission 13, p. 13. 


37 Mr David Robinson, Internet 2.0, Committee Hansard, 20 April 2023, p. 36. 


164 


8.110 ASPI has identified that well-resourced state and non-state actors are misusing 


8.111 Over the course of this inquiry the committee heard compelling accounts 


8.112 The committee heard powerful testimony from individuals personally targeted 


8.113 Ms Vicky Xu, a journalist and policy analyst who was written extensively on the 


This should include building the resilience of Australians, and particularly 
diaspora communities that might be subject to transnational repression and 
foreign interference. This can be achieved by building digital information and 


media awareness. 


all forms of social media to 'facilitate the transnational repression of individuals 
and marginalised communities in Australia’, which is of grave concern for our 


liberal democracy.*8 


diaspora communities and organisations on this rising trend of transnational 
repression. The perspectives of these community groups are uniquely important 
to the committee, as we understand they are often the targets of attempted 
foreign interference and victims of transnational surveillance, repression and 


coercion. 


by foreign interference activities, and these experiences were instructive in 


contemplating how to address these threats. 


human rights abuses of the CCP told the committee: 


I'm still dealing with death threats. I'm still dealing with repeated hacking 
attempts. Just this week I received a dozen hacking attempts across all of my 
accounts ... I've had to adapt the way I live, my lifestyle, to one that's akin 
to a criminal, I would say. People in democracies, politicians, academics and 
people with good social standing tell me things like I'm going to end up in 
history books, and that all sounds grand, but what about life? 


8.114 Similarly, Badiucao told this committee: 


8.115 In relation to an Iranian-Australian woman who has been outspoken on the 


38 


39 


40 


human rights situation in Iran and advocated for the Iranian women's rights 


... there are always certain topics that you cannot talk about. What happens 
is you'll be disappeared or your accounts will be suspended. This is actually 
a typical way of how the Chinese government manages to export its 
censorship outside of China regardless of local law or rights protection in 
Australian society. This is totally contradictory with our values, but 
functionally for Chinese diaspora and other people who are using WeChat, 
we actually have to be subject to China's law, which is not really a law for 
society. This for me is very unfair and fundamentally dangerous to our 
national security and core values of society.” 


Australian Strategic Policy Institute, Submission 13, p. 3. 


Ms Vicky Xu, Senior Fellow, Australian Strategic Policy Institute, Committee Hansard, 21 April 2023, 


p. 35. 


Badiucao, Private capacity, Committee Hansard, 21 April 2023, p. 35. 


165 


movement, Mr Peter Murphy from the Australian Supporters of Democracy in 
Iran, said '[t]he basis of our democratic society include freedom of association, 
freedom of speech and freedom of expression, and this family in Melbourne has 
been told to stop talking, stop attending certain meetings and stop expressing 
certain views. It is really a blatant attack on our basic rights by a foreign 
government’.*! 


8.116 Additionally, Mrs Kateryna Argyou from the Australian Federation of 
Ukrainian Organisations described how the Ukrainian-Australia diaspora is 
dealing with instances of harassment and intimidation: 

We have tried to be very structured and systemised in the way that we 
approach it. Every time we've had a community member who has been 
harassed online or threatened — and we've had many community members 
who've received death threats through Telegram channels, through 
Facebook Messenger and through other social media — we've reported that 
to the police...we'd had over 40 official complaints registered with police.” 


8.117 The impact on individuals who have to live with this fear cannot be overstated. 
Many have fled authoritarian regimes and have chosen to live in Australia 
because of our rule of law and systems of democracy that protect our people 
from repressive tactics designed to silence dissent. Yet these same authoritarian 
states are misappropriating social media channels to reach into our nation to 
continue attempts to silence people through fear and intimidation. Liberal 
democracies like Australia must be resolute that we will not tolerate this 
behaviour and it must end now. 


8.118 Law enforcement agencies and bodies such as the eSafety Commissioner are 
often privy to these personal experiences of coercion and repression, and as such 
are well-placed to share their observations and lessons learned with social 
media platforms and the broader public. 


8.119 With the benefit of this knowledge, individuals and organisations will be better 
placed to make informed choices about their own online activities and identify 
and respond to foreign interference attempts they may be subject to in the 
future. 


Recommendation 14 


8.120 The committee recommends the Australian Government ensure that law 
enforcement agencies, and other relevant bodies such as the 
eSafety Commissioner, work with social media platforms to increase public 
awareness of transnational repression. 


41 Mr Peter Murphy, Co-Secretary, Australian Supporters of Democracy in Iran, Committee Hansard, 


21 April 2023, p. 22. 


42 Mrs Kateryna Argyrou, Co-Chair, Australian Federation of Ukrainian Organisations, 
Committee Hansard, 21 April 2023, p. 28. 


166 


Improving digital and information literacy 

8.121 One of the most effective buffers against foreign interference through social 
media is an informed, resilient population that is capable of identifying 
problematic content on their online feeds. It is vital that an integrated approach 
include supporting and building the resilience of Australians, particularly 
diaspora communities, through improved digital literacy and media awareness. 


8.122 As technology continues to evolve, all Australians must be equipped to 
understand whether the information they are consuming is true or false, 
whether it comes from an authoritative source, whether it is emotionally 
manipulative, and whether they are presented with information from a diversity 
of sources. 


8.123 The Australian Government should take steps to build resilience against foreign 
interference at the individual and community level by providing resources to 
better equip these groups to navigate the fraught digital information landscape. 
Efforts should prioritise at-risk communities, and should consider tailored 
messaging to address the specific needs of these groups. 


Recommendation 15 


8.124 The committee recommends the Australian Government empower citizens 
and organisations to make informed, risk-based decisions about their own 
social media use by publishing plain-language education and guidance 
material and regular reports and risk advisories on commonly used social 
media platforms, ensuring this material is accessible for non-English 
speaking citizens. Specific focus should be on protecting communities and 
local groups which are common targets of foreign interference and provide 
pre-emptive information and resources. 


Independent media 

8.125 The committee has been reminded of the role of news media in providing 
reliable, accurate and apolitical news about politics and current events. It has 
received evidence about the potential dangers associated with consuming news 
content through social media, and the dangers of accessing information in an 
‘echo chamber’ where people only encounter information or opinions which 
reflect and reinforce their own worldviews because of algorithmic preferences. 


8.126 Furthermore, evidence heard by the committee shows authoritarian states 
control news and other content on some social media platforms used by 
Australians. For example, ASPI cited leaked content moderation documents 
which revealed that TikTok previously instructed its moderators to censor 
videos that mention Tiananmen Square, Tibetan independence, or the banned 
religious group Falun Gong.* This demonstrates the ways in which information 


43 Mr Fergus Ryan, Australian Strategic Policy Institute, Committee Hansard, 20 April 2023, p. 18-19. 


167 


can be filtered and manipulated to support the strategic interests of the 
interfering country, often in ways inimical to our own interests. 


8.127 The committee heard of the specific challenges posed by TikTok and WeChat, 
given their ownership structures and the operation of Chinese national security 
laws. It also heard evidence of surveillance and restrictions of freedom of 
expression of Iranian- and Ukrainian-heritage people in Australia. 


8.128 However, the committee also heard that independent reporting in the original 
languages of diaspora communities in Australia could play a key role in 
countering disinformation, content moderation, propaganda, censorship, and 
foreign influence through social media. 


8.129 Witnesses explained that independent journalism provides diaspora 
communities with neutral and reliable sources of news about politics and 
current events. As noted by legal expert submitters, 'news and journalism 
generate significant benefits for society through the "production and 
dissemination of knowledge, the exposure of corruption, and holding 
Governments and other decision-makers to account".* 


Recommendation 16 


8.130 The committee recommends the Australian Government support 
independent and professional foreign-language journalism by supporting 
journalism training and similar programs, thereby expanding the sources of 
uncensored news for diaspora communities to learn about issues such as 
human rights abuses inside their country of origin. 


Protecting our neighbours 

8.131 Australia has a strong, longstanding relationship with its Pacific neighbours. 
Australia's security cooperation with Pacific countries covers defence, law 
enforcement, transnational crime, climate and disaster resilience, border 
management and human security. 


8.132 While the Australian Government is working with our Pacific neighbours 
through the Cyber and Critical Technology Cooperation Program to increase 
information technology resilience of governments and civil society we need to 
do more to specifically address the impacts that foreign interference can have 
both on governments and ordinary people across our neighbouring regions. 


8.133 The Australian Government should consider ways to extend the learnings and 
benefits of the other initiatives recommended by this report to our regional 
neighbours. These efforts will build country-to-country linkages, and empower 
our neighbours to identify and thwart foreign interference attempts within their 
own communities. 


‘44 The Law Society of New South Wales Young Lawyers, Submission 33, p. 17. 


168 


Recommendation 17 


8.134 The committee recommends the Australian Government promote the digital 
literacy and the infrastructure of developing countries in the Indo-Pacific 
region that are the targets of malicious information operations by foreign 
authoritarian states. 


Senator James Paterson 
Chair 
Liberal Senator for Victoria 


Additional comments from Government Senators 


1.1 


1.2 
1.3 


1.4 


1.5 


1.6 


1.7 


1.8 


1.9 


1.10 


1.11 


1.12 


We thank the committee Chair, Senator Paterson, and committee members for 
conducting a comprehensive inquiry on a matter of national significance in a 
collegiate spirit. 


The risk of foreign interference is real across all social media platforms. 


Misinformation and disinformation, coordinated inauthentic behaviour (CIB) 
and foreign interference through social media pose a threat to Australia's social 
cohesion, national security and to the ability of diaspora communities to 
participate fully and without fear in our democracy. 


Platforms must take greater responsibility for combating these harmful 
practices. 


While evidence from platforms indicated they have some measures in place, 
there are significant differences and gaps in platform practices and reporting. 
Overall, platform transparency measures are insufficient and inconsistent, 
particularly when it comes to specific reporting on the Australian context. 


The committee has recommended a minimum set of transparency requirements, 
enforceable with fines. Government Senators welcome the committee's core 
focus on transparency measures. 


In January 2023, the Minister for Communications announced that the 
Australian Government would introduce new laws to provide the independent 
regulator, the Australian Communications and Media Authority (ACMA), with 
new powers to combat online misinformation and disinformation. 


The new powers will enable the ACMA to require platforms to address 
misinformation and disinformation, while balancing freedom of speech. 


The proposed powers mirror those proposed by the committee, and will enable 
the ACMA to gather information from platforms and require them to keep 
records about misinformation and disinformation. 


Evidence to this inquiry has further highlighted the urgent need for powers like 
these, to ensure consistent, transparent, Australia-focussed information is 
available from platforms to inform users. 


The proposed legislation also gives the ACMA the power to enforce an 
industry-led code of practice covering measures to combat misinformation and 
disinformation, and to create and enforce a new industry standard, if required. 


The committee has proposed a list of specific requirements that could be 
considered as part of such a new code, including requiring social media 
platforms to have an Australian presence to ensure accountability to the 
Parliament and people, labelling state-affiliated media, disclosing instances of 


169 


170 


1.13 


1.14 


1.15 


1.16 


1.17 


1.18 


1.19 


1.20 


transnational repression, and greater transparency about levels of CIB and 
takedowns of networks and materials. We commend the list of measures in 
Recommendation One for further consideration by the Australian Government. 


Blunt, national bans of specific platforms as a policy approach were not 
supported by evidence to the committee. 


One submitter described single platform bans as a 'whack-a-mole approach', 
given the relative ease with which platforms could take data and reestablish, 
and the frequency with which new platforms emerge in the global market. 
Others raised concerns about whether bans can be practically implemented, and 
the implications for users on these platforms. 


For these reasons, the committee's central focus is on strong regulation for 
transparency, rather than nation-wide bans of specific platforms. 


In relation to bans on government devices, the Australian Government has 
taken an appropriate and targeted approach, by seeking advice from 
intelligence and security agencies and issuing a mandatory direction under the 
Protective Security Policy Framework to prohibit TikTok on devices issued by 
Australian Government departments and agencies. 


We note that any further approaches to bans or policies for government or 
government-related devices should similarly be informed by advice from 
agencies. 


The committee notes that a whole-of-government approach is required to 
combat foreign interference through social media. Departments and agencies 
including Home Affairs, the Australian Federal Police, Australian Electoral 
Commission, the eSafety Commissioner and intelligence agencies gave evidence 
of their collaboration today to protect Australians. Home Affairs, as the lead 
department in countering foreign interference, outlined the central role of the 
Counter Foreign Interference Coordination Centre (CFICC) within 
Home Affairs in leading multi-department and agency collaboration. 


One of the most concerning themes in evidence was instances of harassment of 
Australian citizens within diaspora communities as they exercise their 
democratic rights to speak out on matters pertaining to their country of origin. 
This whole-of-government approach is needed to protect at-risk communities. 
Work to continually improve the resources of, and responses to, diaspora 
communities is critical. The committee recommends supporting diverse, 
independent foreign-language journalism in Australia, as part of this approach. 


We note that the committee has provided a range of further thoughtful 
recommendations for the consideration of the Australian Government, 
including in the areas of the security implications of artificial intelligence (AI), 
supporting independent research, and further assisting our Pacific neighbours 
to combat foreign interference in the region. 


171 


1.21 Once more, we thank the Chair, committee members, submitters and witnesses 
and the Secretariat for their considered work on a topic of critical importance to 


our nation. 
Senator Jess Walsh Senator Raff Ciccone 
Deputy Chair Member 


Labor Senator for Victoria Labor Senator for Victoria 


1.1 


1.2 


1.3 


1.4 


Australian Greens' Additional Comments 


The Greens welcome the committee’s recommendations for a minimum set of 
transparency requirements which social media companies must comply with 
and which are enforceable with fines. 


The recommendations fail to further include data minimisation requirements 
which protect the sensitive data of users and their digital rights. 


The Greens do not support platform-specific reforms because this fails to tackle 
the core of the issue. We urgently need a platform-neutral approach to policy 
because targeting a single platform based on the country it is linked to does 
nothing to protect Australians from foreign interference. 


Banning TikTok or any other singular platform from government devices is 
nothing but a game of digital whack-a-mole and does nothing to protect 
Australians. Bad actors will use their vast resources through whatever means 
necessary to meet their objectives and until we address the underlying causes 
Australians will continue to be subject to foreign interference threats. 


Senator Sarah Hanson-Young Senator David Shoebridge 
Member Member 
Greens Senator for South Australia Greens Senator for New South Wales 


173 


NO FF PWN = 


Appendix 1 
Submissions, tabled documents and additional 
information 


Department of Home Affairs 

Australian Security Intelligence Organisation 
University of Adelaide, Defence Security Institute 
U.S. Federal Communications Commission 
Australian Signals Directorate 

Australian Communications and Media Authority 
Department of Infrastructure, Transport, Regional Development, 
Communications and the Arts 

Australian Electoral Commission 

Australian Human Rights Commission 

eSafety Commissioner 

e 10.1 Supplementary to submission 10 

e Attachment 1 


RAND Australia 

Human Rights Watch 

Australian Strategic Policy Institute 
SBS 

WeChat 

CyberCx 

Internet 2.0 

e Attachment 1 


Dr William Stoltz 

Allens Hub joint submission (UNSW Allens Hub; Deakin CSRI; IEEE SSIT) 
Ms Sarah Kendall 

News & Media Research Centre 

Dr Samuel White 

Australian Supporters of Democracy in Iran 

e 23.1 Supplementary to submission 23 


Australian Muslim Advocacy Network 
Attorney-General's Department 

Reset Australia 

Law Council of Australia 

University of Melbourne, UNSW, University of Adelaide 
Internet Governance Project, Georgia Tech 

e Attachment 1 


175 


176 


30 
31 
32 
33 
34 
35 
36 
37 
38 
39 
40 


TikTok Australia 

Australian Tibetan Communities Association 
Meta Australia 

NSW Young Lawyers 

Rachel Lee, Prudence Luttrell, Matthew Johnson, John Garnaut 
Digi Industry Group Inc 

Simon Jiandan 

Professors Wanning Sun & Haiqing Yu 
Confidential 

Ms Vanessa Teague 

Confidential 


Tabled Documents 


1 


Document tabled by Senator David Van at a public hearing in Canberra, 21 
April 2023. 

Document tabled by Senator James Paterson at a public hearing in Canberra, 
12 July 2023. 


Answer to Question on Notice 


1 
2 


12 


13 


LinkedIn, answers to questions on notice,11 July 2023 (received 14 July 2023) 
ACMA, answer to questions on notice No. 1, 12 July 2023 (received 14 July 
2023) 
ACMA, answer to questions on notice No. 2, 12 July 2023 (received 14 July 
2023) 
ACMA, answer to questions on notice No. 3, 12 July 2023 (received 14 July 
2023) 
ACMA, answer to questions on notice No. 4, 12 July 2023 (received 14 July 
2023) 
ACMA, answer to questions on notice No. 5, 12 July 2023 (received 14 July 
2023) 
ACMA, answer to questions on notice No. 6, 12 July 2023 (received 14 July 
2023) 

Attorney-General's Department, answer to questions on notice, 12 July 2023 
(received 17 July 2023) 

TikTok Australia, answers to questions on notice (1, 9, 10) 11 July 2023 
(received 14 July 2023) 

TikTok Australia, answers to written questions on notice (5) 11 July 2023 
(received 17 July 2023) 

Department of Home Affairs, answers to questions on notice (no. 1) 12 July 
2023 (received 18 July 2023) 

Department of Home Affairs, answers to questions on notice (no. 2) 12 July 
2023 (received 18 July 2023) 

Department of Home Affairs, answers to questions on notice (no. 3) 12 July 
2023 (received 18 July 2023) 


177 


14 


15 


16 


17 


18 


19 


20 


21 


22 


23 


24 


25 


26 


27 


28 
29 


Department of Home Affairs, answers to questions on notice (no. 4) 12 July 
2023 (received 18 July 2023) 

Department of Home Affairs, answers to questions on notice (no. 5) 12 July 
2023 (received 18 July 2023) 

Department of Home Affairs, answers to questions on notice (no. 6) 12 July 
2023 (received 18 July 2023) 

Department of Home Affairs, answers to questions on notice (no. 7) 12 July 
2023 (received 18 July 2023) 

TikTok Australia, answers to written questions on notice (2, 3, 4) 11 July 2023 
(received 19 July 2023) 

TikTok Australia, answers to questions on notice (2, 3, 7, 8) 11 July 2023 
(received 19 July 2023) 

Australian Electoral Commission, answer to question on notice, IQ23-000002, 
12 July 2023 (received 19 July 2023) 

Meta Australia, answers to questions on notice (1-9) 11 July 2023 (received 19 
July 2023) 

Meta Australia, answers to written questions on notice (1-11) 11 July 2023 
(received 19 July 2023) 

TikTok Australia, answers to questions on notice (4, 5, 6), 11 July 2023 
(received 21 July 2023) 

TikTok Australia, answers to written questions on notice (1), 11 July 2023 
(received 21 July 2023) 

Twitter, answers to questions on notice,11 July 2023 (received 25 July 2023) 
Twitter, answers to questions on notice,11 July 2023 (received 25 July 2023) 
We Chat, answers to written questions on notice, 17 July 2023 (received 26 
July 2023) 

TikTok, answers to questions on notice (6) 11 July 2023 (received 26 July 2023) 
TikTok Australia, answers to questions on notice (7 annexure) 11 July 2023 
(received 19 July 2023) 


Appendix 2 
Public hearings and witnesses 


Thursday, 20 April 2023 
Committee Room 253 
Parliament House 
Canberra 


Ms Shanthi Kalathil (via videoconference), Private capacity 


U.S. Federal Communications Commission (via videoconference) 
e Commissioner Brendan Carr, Commissioner 


Dr Seth Kaplan (via videoconference), Private capacity 


Australian Strategic Policy Institute 
e Mr Fergus Ryan, Senior Analyst 
e Mr Albert Zhang, Analyst 
e Ms Emily Mosley, International Cyber Policy Centre Coordinator 


RAND Australia 
e Dr Andrew Dowse, Director 


Internet 2.0 (via videoconference) 
e Mr David Robinson, Director 


Dr William Stoltz (via videoconference), Private capacity 


Professor Rory Cormac (via videoconference), Private capacity 


Friday, 21 April 2023 
Committee Room 253 
Parliament House 
Canberra 


Human Rights Watch 
e Ms Elaine Pearson, Asia Director 
e Ms Yagiu Wang, Senior China Researcher (via videoconference) 


Alliance for Securing Democracy 


e Ms Lindsay Gorman, Senior Fellow and Head of the Technology and 


Geopolitics Team (via videoconference) 


179 


180 


Mr Kenny Chiu (via videoconference), Private capacity 


Australian Supporters of Democracy in Iran 
e Mr Peter Murphy, Co-Secretary 


Australian Tibetan Communities Association 
e Mr Kalsang Tsering, President (via videoconference) 


Australian Federation of Ukrainian Organisations 
e Mrs Kateryna Argyrou, Co-Chair 


Vicky Xu (via videoconference), Private capacity 
Badiucao (via videoconference), Private capacity 


Tuesday, 11 July 2023 


Main Committee Room 
Parliament House 
Canberra 


Meta Australia 
e Mr Josh Machin, Head of Public Policy, Australia 


Meta Australia 
e Ms Mia Garlick, Director of Policy Australia and New Zealand 


LinkedIn 
e Mr Joshua Reiten, Senior Director, Digital Safety 


TikTok Australia 
e Ms Ella Woods-Joyce, Director of Public Policy 


TikTok Australia 
e Mr Will Farrell, US Data Security 


TikTok Australia 
e Mr Lee Hunter, General Manager, Australia 


Google 
e Mr Shane Huntley, Senior Director and Global Lead, Google Threat 
Analysis Group 


You Tube Australia 
e Ms Rachel Lord, Senior Manager, Public Policy and Government Relations 


Twitter 
e Ms Kathleen Reen, Senior Director of Public Policy, JAPAC 


181 


Twitter 
e Mr Nick Pickles, Head of Global Government Affairs 


Wednesday, 12 July 2023 
Main Committee Room 
Parliament House 
Canberra 


Department of Home Affairs 
e Ms Sally Pfeiffer, A/g FAS Counter Foreign Interference 
e Mr Peter Anstee, A/g FAS Digital Security Policy 


Australian Security Intelligence Organisation 
e Mr Mike Noyes, Deputy Director-General, Intelligence Service Delivery 


Australian Signals Directorate 
e Ms Abigail Bradshaw, Acting Director-General 
e Ms Stephanie Crowe, Acting Head Australian Cyber Security Centre 
e Mr Daniel Tripovich, Assistant Director-General Standards, Technical 
Advice and Research 


Attorney-General’s Department 
e Mr Parker Reeve, Assistant Secretary: Transparency and Administration 
Law 
e Ms Catherine Fitch, A/g First Assistant Secretary, Integrity Frameworks 
Division 
e Ms Sarah Chidgey, Deputy Secretary, National Security and Criminal 
Justice 


Australian Federal Police 
e Mr Christopher Goldsmid, Commander Cybercrime Operations, 
Cyber Command 
e Mr Stephen Nutt, Commander Special Investigations, Counter Terrorism 
and Special Investigations Command 


Australian Communications and Media Authority 
e Ms Cathy Rainsford, General Manager, Content & Consumer Division 
e Ms Nerida O'Loughlin, Chair 


Office of the eSafety Commissioner 
e Mr Toby Dagg, Acting eSafety Commissioner 


182 


Department of Infrastructure, Transport, Regional Development, Communications and the 
Arts 
e Mr Sam Kursar, Director, Information Integrity Section 
e Mr Andrew Irwin, Acting Assistant Secretary, Platforms and News Branch 
e Mr Richard Windeyer, Deputy Secretary, Communications and Media 
Group 


Australian Electoral Commission 
e Mr Tom Rogers, Electoral Commissioner 
e Mr Jeff Pope, Deputy Electoral Commissioner 


Appendix 3 
46th Parliament inquiry recommendations 


Recommendations from interim report of 46th Parliament 


1.1 


The following section details the recommendations made by the Select 
Committee on Foreign Interference through Social Media in the 46" Parliament, 
and any progress on those recommendations as at February 2023. 


Recommendation 1 


1.2 


The committee recommends that the Australian Government clearly 
delegate lead accountability for cyber-enabled foreign interference to a 
single entity in government. 


Lead accountability continues to be shared across Government, including by the 
Department of Home Affairs, the Australian Security and Intelligence 
Organisation (ASIO), and the Australian Federal Police (AFP), with the 
Counter Foreign Interference Taskforce sitting within Home Affairs. However, 
it is also evident that there remain a number of key departments in this space, 
including also the Attorney-General's Department (including the 
National Security Hotline), the Department of Foreign Affairs and Trade 
(DFAT) and Department of Finance, as well as agencies including the Australian 
Electoral Commission (AEC), the Australian Communications and Media 
Authority (ACMA), and the Australian Competition and Consumer 
Commission (ACCC ).! 


Recommendation 2 


1.3 


1 


The committee recommends that the Australian Government take a 
proactive approach to protecting groups that are common targets of foreign 
interference but are not classified as government institutions. 


On 14 February 2023, the Minister for Home Affairs announced a new 
community outreach program to be coordinated by Home Affairs and ASIO. 
The program will identify individuals within the Australian community who 
might be targets of foreign interference and design and deliver a program to 
proactively help them understand what foreign interference is, how they can 
respond, and what the Government can do to protect them. This is in addition 
to the existing Home Affairs counter interference engagement officers in each 


ACMA, Release of ACMA’s disinformation report, 21 March 2022; Australian Competition and 
Consumer Commission, ACCC September 2022 Digital Platform Services Inquiry Report on Regulatory 


Reform — Key Findings, [2022]. 


183 


184 


1.4 


state and territory, who work with a 'network of people who we believe might 
be targeted in engagements of foreign interference’. 


On 27 February 2023, the AFP announced the launch of an education campaign 
to help culturally and linguistically diverse communities (CALD) understand 
what FI is, how it manifests itself and where victims can report instances and 
seek assistance. It will include a factsheet, translated into more than 30 
languages and meetings between AFP community liaison teams and CALD 
groups and religious leaders.’ 


Recommendation 3 


1.5 


1.6 


1.7 


The committee recommends that the Australian Government establish 
appropriate, transparent, and non-political institutional mechanisms for 
publicly communicating cyber-enabled foreign interference in our elections 
and review the processes and protocols for classified briefings for the 
Opposition during caretaker with respect to cyber-enabled foreign 
interference. 


Established in 2019, the role of the Electoral Integrity Assurance Taskforce is to 
safeguard Australia's electoral integrity. The Taskforce provides a mechanism 
for sharing and referring relevant information (including foreign interference 
material) between relevant agencies.‘ 


The AEC is aware of the threat to democracy of mis and disinformation, 
including through social media, and in 2021 released a Reputational 
Management Strategy and complementary Disinformation Register (for current 
election events).° 


Guidance on caretaker conventions were updated in December 2021 and 
currently contain no specific guidance on classified briefings for the Opposition 
during the caretaker period with respect to foreign interference, noting that the 
ASIO Act already makes provision for the Leader of the Opposition to be 


The Hon Clare O'Neil MP, Minister for Home Affairs, Foreign interference in Australia— ANU address, 
14 February 2023, [p. 5]. 


Australian Federal Police, ‘AFP launches new resource to help combat foreign interference’, Media 
release, 27 February 2023, (accessed 27 February 2023). 


Electoral Integrity Assurance Taskforce, Australian Electoral Commission, Foreign interference 


[factsheet]. See also: Australian National Security, Report suspicious behaviour, 
www.nationalsecurity.gov.au/what-can-i-do/report-suspicious-behaviour (accessed 15 February 
2023); Department of Home Affairs, Countering foreign interference, www.homeaffairs.gov.au/about- 
us/our-portfolios/national-security/countering-foreign-interference (accessed 15 February 2023). 


Australian Electoral Commission, Electoral integrity: Reputation Management Strategy, 2021, pp. 3-4; 
Australian Electoral Commission, Disinformation register, https://aec.gov.au/media/ disinformation- 
register.htm (accessed 15 February 2023). 


185 


‘consulted regularly ... for the purpose of keeping him or her informed on 
matters relating to security'.® 


Recommendation 4 


1.8 
1.9 


The committee recommends that the Australian Communications and 
Media Authority's report into the functioning of the Australian Code of 
Practice on Disinformation and Misinformation be publicly released as a 
matter of priority. 


The report was completed in June 2021 and released on 21 March 2022.7 


Annual transparency reports about the functioning of The Australian Code of 
Practice on Misinformation and Disinformation (DIGI code) are also published 
by Digital Industry Group Inc (DIGI).* 


1.10 In December 2022, DIGI strengthened the code, making changes in response to 


stakeholder feedback received through a planned review of the code. Changes 
included an improved definition of ‘harm’ in relation to mis and disinformation 
and additional commitments reflecting updates to the strengthened European 
Union Code of Practice. DIGI also introduced more proportionate annual 
transparency reporting requirements for smaller platforms to encourage them 
to adopt the code, which can be flexibly applied to different types of digital 
service providers. 


1.11 These updates are the latest set in a series of improvements driven by DIGI and 


code signatories since the DIGI code was introduced in February 2021. In 
October 2021, DIGI introduced independent oversight and a complaints facility 
to increase accountability. In 2022, independent assessment and best practice 
reporting guidelines were introduced to drive improvements in the 
transparency reporting process.’ 


Recommendation 5 


The committee recommends that the Australian Government publicly 
release the Electoral Integrity Assurance Taskforce's terms of reference. 


Australian Security Intelligence Organisation Act 1979, s. 21. 


Australian Communications and Media Authority, Report to government on the adequacy of digital 


platforms’ disinformation and news quality measures, June 2021; Australian Communications and 
Media Authority, Release of ACMA’s disinformation report, 21 March 2022, 


www.acma.gov.au/articles/2022-03/release-acmas-disinformation-report (accessed 23 February 
2023). 


DIGI, Transparency reports, https://digi.org.au/disinformation-code/transparency/ (accessed 15 
February 2023). 


DIGI, DIGI Welcomes The Government Providing ACMA With Oversight Powers Over Misinformation, 
20 January 2023, https://digi.org.au/digi-welcomes-the-government-providing-acma-with- 


oversight-powers-over-misinformation/ (accessed 23 February 2023). 


186 


1.12 The terms of reference were published 27 October 2022.1 


Recommendation 6 
The committee recommends that the Australian Government establish clear 
requirements and pathways for social media platforms to report suspected 
foreign interference, including disinformation and coordinated inauthentic 
behaviour, and other offensive and harmful content, and formalise agency 
remits, powers and resourcing arrangements accordingly. 


1.13 The nature of arrangements, including reporting arrangements, with social 
media platforms are not publicly available. 


1.14 As part of the DIGI code signatories, including social media platforms, commit 
to identify and address mis and disinformation: 
As part of this [Complaints] process, Signatories will also consider how they 
can leverage current arrangements with government and relevant 
regulatory agencies to identify and address instances of Inauthentic 


Behaviours that propagate Disinformation and are the subject of measures 
addressed by this Code." 


1.15 Following the release of its June 2021 report, the ACMA anticipated that the 
Government would establish the Misinformation and Disinformation Action 
Group (MADAG) to support collaboration and information-sharing between 
key stakeholders on issues relating to disinformation and misinformation.” 


Recommendation 7 
The committee recommends that the Election Integrity Assurance Taskforce 
undertake an audit to assess capability relevant to detecting disinformation 
prior to the coming election and, further, that the Australian Government 
consider providing information about relevant capabilities and resourcing 
to this committee as appropriate to assist in our deliberations. 


1.16 In general terms, under the Taskforce's terms of reference it is responsible for 
‘assessing and understanding the vulnerability of Australia’s federal electoral 
environment, and developing strategies and processes to ensure cohesive and 
effective management and response should any threats be realised’. 


1.17 Public information about the Taskforce's work is limited. 


0 Australian Electoral Commission, Electoral Integrity Assurance Taskforce: terms of reference, 27 October 
2022. 


1 DIGI, Australian code of practice on disinformation and misinformation, Updated 22 December 2022, 
p. 21. 


Department of Infrastructure, Transport, Regional Development, Communications and the Arts, 
Media release: New disinformation laws, 21 March 2022. 


Australian Electoral Commission, Electoral Integrity Assurance Taskforce: terms of reference, 27 October 
2022, p. 1. 


